!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/etc/gconf/2/   drwxr-xr-x
Free 52.26 GB of 127.8 GB (40.89%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     evoldap.conf (3.32 KB)      -rw-r--r--
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
<evoldap>
  <server>
    <host></host> <!-- e.g. ldap.blaa.com -->
    <port></port> <!-- defaults to 389 -->
    <base_dn></base_dn> <!-- e.g. ou=people,dc=blaa,dc=com -->
  </server>

  <!--
     The values of the following keys:
       - /apps/evolution/mail/accounts
       - /apps/evolution/addressbook/sources
       - /apps/evolution/calendar/sources
       - /apps/evolution/tasks/sources
     will be constructed by applying each LDAP entry which matches
     the "filter" attribute on the <template> tag to the template
     template corresponding to the key.

     If the filter returns multiple values, the value of the GConf
     key will be a multiple element list.

     Valid variables:
       1) $(USER) - the username
       2) $(EVOLUTION_UID) - mystical magical per-account UID string
       3) $(LDAP_ATTR_foo) - the value of the "foo" attribute on the
                             LDAP entry which matches the filter
    -->

  <template filter="(&amp;(uid=$(USER))(objectClass=inetOrgPerson)(objectClass=evolutionMailAccount)(objectClass=evolutionAddressbookSource)(objectClass=evolutionCalendarSource)(objectClass=evolutionTasksSource))">

    <!-- /apps/evolution/mail/accounts -->
    <account_template>
      <account name="$(LDAP_ATTR_mail)" uid="$(EVOLUTION_UID)" enabled="true">
        <identity>
          <name>$(LDAP_ATTR_cn)</name>
          <addr-spec>$(LDAP_ATTR_mail)</addr-spec>
          <reply-to></reply-to>
          <organization></organization>
          <signature uid=""/>
        </identity>
        <source save-passwd="false" keep-on-server="false" auto-check="false" auto-check-timeout="10">
          <url>$(LDAP_ATTR_evolutionMailSourceURI)</url>
        </source>
        <transport save-passwd="false">
          <url>$(LDAP_ATTR_evolutionMailTransportURI)</url>
        </transport>
        <drafts-folder></drafts-folder>
        <sent-folder></sent-folder>
        <auto-cc always="false">
          <recipients></recipients>
        </auto-cc>
        <auto-bcc always="false">
          <recipients></recipients>
        </auto-bcc>
        <pgp encrypt-to-self="false" always-trust="false" always-sign="false" no-imip-sign="false">
          <key-id></key-id>
        </pgp>
        <smime sign-default="false" encrypt-default="false" encrypt-to-self="false">
          <sign-key-id></sign-key-id>
          <encrypt-key-id></encrypt-key-id>
        </smime>
      </account>
    </account_template>

    <!-- /apps/evolution/addressbook/sources -->
    <addressbook_template>
      <group uid="$(EVOLUTION_UID)" name="Addressbook" base_uri="" readonly="no">
        <source uid="$(EVOLUTION_UID)" name="Addressbook" relative_uri="" uri="$(LDAP_ATTR_evolutionAddressbookURI)"/>
      </group>
    </addressbook_template>

    <!-- /apps/evolution/calendar/sources -->
    <calendar_template> 
      <group uid="$(EVOLUTION_UID)" name="Calendar" base_uri="" readonly="no">
        <source uid="$(EVOLUTION_UID)" name="Calendar" relative_uri="" uri="$(LDAP_ATTR_evolutionCalendarURI)"/>
      </group>p
    </calendar_template>

   <!-- /apps/evolution/tasks/sources -->
   <tasks_template>
      <group uid="$(EVOLUTION_UID)" name="Tasks" base_uri="" readonly="no">
        <source uid="$(EVOLUTION_UID)" name="Tasks" relative_uri="" uri="$(LDAP_ATTR_evolutionTasksURI)"/>
      </group>
    </tasks_template>

  </template>

</evoldap>

:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ Read-Only ]

:: Make Dir ::
 
[ Read-Only ]
:: Make File ::
 
[ Read-Only ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0052 ]--