!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/etc/dbus-1/system.d/   drwxr-xr-x
Free 50.94 GB of 127.8 GB (39.86%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     oddjob.conf (2.75 KB)      -rw-r--r--
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
<!DOCTYPE busconfig PUBLIC
 "-//freedesktop//DTD D-BUS Bus Configuration 1.0//EN"
 "http://www.freedesktop.org/standards/dbus/1.0/busconfig.dtd">

<busconfig>

  <!-- This configuration file specifies the required security policies
       for the oddjob service to work.  It controls which requests users
       will be allowed to issue to oddjobd over the bus, which is quite
       different from controlling whether or not oddjobd will attempt to
       fulfill the request. -->

  <!-- Only root can own the oddjob service -->
  <policy user="root">
    <allow own="com.redhat.oddjob"/>
  </policy>

  <!-- Allow anyone to call the quit method of the
       com.redhat.oddjob interface implemented by the
       /com/redhat/oddjob object provided by the
       com.redhat.oddjob service -->
  <policy context="default">
    <allow send_destination="com.redhat.oddjob" send_path="/com/redhat/oddjob" send_interface="com.redhat.oddjob" send_member="quit"/>
  </policy>

  <!-- Allow anyone to call the mkhomedirfor method of the
       com.redhat.oddjob interface implemented by the
       /com/redhat/oddjob object provided by the
       com.redhat.oddjob service -->
  <policy context="default">
    <allow send_destination="com.redhat.oddjob" send_path="/com/redhat/oddjob" send_interface="com.redhat.oddjob" send_member="mkhomedirfor"/>
  </policy>

  <!-- Allow anyone to call the mkmyhomedir method of the
       com.redhat.oddjob interface implemented by the
       /com/redhat/oddjob object provided by the
       com.redhat.oddjob service -->
  <policy context="default">
    <allow send_destination="com.redhat.oddjob" send_path="/com/redhat/oddjob" send_interface="com.redhat.oddjob" send_member="mkmyhomedir"/>
  </policy>

  <!-- Allow anyone to call the list method of the
       com.redhat.oddjob interface implemented by the
       /com/redhat/oddjob object provided by the
       com.redhat.oddjob service -->
  <policy context="default">
    <allow send_destination="com.redhat.oddjob" send_path="/com/redhat/oddjob" send_interface="com.redhat.oddjob" send_member="list"/>
  </policy>

  <!-- Allow anyone to call the reload method of the
       com.redhat.oddjob interface implemented by the
       /com/redhat/oddjob object provided by the
       com.redhat.oddjob service -->
  <policy context="default">
    <allow send_destination="com.redhat.oddjob" send_path="/com/redhat/oddjob" send_interface="com.redhat.oddjob" send_member="reload"/>
  </policy>

  <!-- Allow anyone to call the introspection methods of the
       /com/redhat/oddjob object provided by the
       com.redhat.oddjob service -->
  <policy context="default">
    <allow send_destination="com.redhat.oddjob" send_path="/com/redhat/oddjob" send_interface="org.freedesktop.DBus.Introspectable"/>
  </policy>

</busconfig>

:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ Read-Only ]

:: Make Dir ::
 
[ Read-Only ]
:: Make File ::
 
[ Read-Only ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0107 ]--