!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/usr/bin/   drwxr-xr-x
Free 52.29 GB of 127.8 GB (40.92%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     curl (57.63 KB)      -rwxr-xr-x
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
ELFp44 (444444  c c66 c cHHH PtdXXMXM44Qtd/lib/ld-linux.so.2GNU S! SW]ݺ|(CE#eh>e<eQeQe`0eL0e^^^^^_D4_e8_<_L_e__e___̿п0ԿؿܿٳЏeooeoe1e2eii oii yii ii ii 8d eYe[eUHdLdPdTdXd\d`dddhd ld pd td xd|dddddddddddddddddd d!d"d#d$d%d&d'd(d)d*d+d,d-d.d/e0e1e2 e3e4e5e6e7 e8$e9(e:,e;0e<4e=8e>PZD$$ (B%@$ 0<+ <- q=T~lǂWǀBǁ -ǂ ǀ ǁF</$>F<$L?$DD$eP tG$eP tӉD$$=Cu$ex$1d e@DAt@A$=D$(ʋ|$ڸ lXp@pD$$5,l~,Dž,Dž00DB uD$\$$CP,|$ t$D$f$~! t€u҉)! t€uҋ,)Ȁxy@Xj;, D$,$lDžt$ @ C9EwӋED$D$$D$ /;uu9}1HE.B<_wʉL$MD$I $}tZ9uvxE>)9tl}uC9EvE؀8 uU| ED$.D$I$At&C9EvE| u| u+E<0U$ T$}9}M $HA'R q]ą뒋$D$Ie+E<0CM1Mt\0;]sKE< u=e)D$ET$ D$މ$Oe밃)=eu%E؉$D$ AD$D$;ET$ D$\$$lM $D$;-tD $TL9~uou<뼉t$$Pt ƅoȍG19~ $TL"Tt넋TDžt itHƅn"t+"Džh诽 nDžLFv1tDžL$DžL#$fDžLDžL$-;"$D$q$sc tDž|8tC: :B e||Dž\@@eDžDž BDžt$跾I uQtM1\t"D$ \D$D$d$.L"Dždd„t u*d $%x!1\tD$ `D$D$h$-L!D$$DžDžpDžtDžhl$$DžXt $X@UXX$T$Mht0D$X$"X $艹X  X  yuT$X$y*ƅD$ $`gD$$BtPD$/$5t >D$/$ ÅD$\$D$D$<$$T $ËT$D$輹{TT$ D$$L$覺T $ط$誷D$9$D$$L$@zƅpt tDžDžD$$L$t$$$\t p`~YsuPXT$D$ T$D$D$e$訹hD$$ַtPD$/$ɵD$?$/ƅS&$h $ҶD$薷hD$SD$ D$$T$u$臵LD$t\$D$ t$D$4$R똡eD$$D$bl?($ D$4$$zDžLtD$D$q<$q`DžD5\$ D$D$4$dD$D$y<$D$D$o<$Dž`hL$ D$$D$xD$4$m/Ifd 4t$D$[e$ۡ4$裞$蕞t&D$$L$nDžDžD$D$o<$D$D$q<$˜L$$ݠ,D$D$o<$p@D$ `D$D$$Š"ۋ/C'TD$ D$$T$+4$> $0eVBt$  $|Ëhth$Ŝt$賜<$ 8ttt$ntt$QTDžTD$D$@<$訚T$&v$CD$[u狅T$蒜DžLDž|Zt$$D$RlD$D$$D$ Pƅn=$Fh$BpDž%҃ت8h$DžL$:C$КM$Mb$ ܜ詟t$D$e$觝$tEzt$D$ e${t$D$e$]}t$D$e$?_t$D$`e$!A$X$|T$ߦDžLG$D$I*$舙DžLzdt$Dždt $EBt$0At$B Dž$WDžLy$|D$DžLTe#X$舘|UWVSEE싀x9w+QfME@z(tYE9v(uыM$E9w؋U싂$MM[^_]ڗR0փx*EUMD ,$誗uUMRD,$萗X UWVS\E eU1҉EEE$CE$E EEM]U9]w E ML$$ԕ EEEt$|$$賗]}<#_uW_DPtED$ D$ D$$cMP9MRD HMċX ]ȋPŰPUЋPUԋ@Etkt~L$$I+E$ EUe3E\[^_]ËMEًU$EEʍ}޾EEEЍ]މT$D$LID$D$ $}$腖jE΋<<$oTC&UWVS,}E쀿 KƇ 1MtH@D H@D$$I$חD$D$ UT$E$蒖E)E9vEE,[^_]rUAU뿋AD$A D$LID$ ED$U$"E)EQ A$E\$ D$UT$E$UU)UMX[t ;sqFVt1tGB f;BfB tfB 뼋BB:BBTBB݋BB;BB9BBÃ,1[^_]Ð&UWVSӃ\EtA{t<[t7}K]t&=\uU$ʕM[t1{\[^_]ÍCEĉ@}Ѝ| WAEU躒ESPHEGD$ED$ED$ED$ ED$D$I]ĉ$觔U}Ѝ D$JD$P$|$ Ǔ}$ّ\[^_]ID P}̍{U@fBfB $OMA<\t5<,"<[ KW׉˃E<\uˍWUW],[t&UȍKf"G}EfG D$ED$ED$ED$ ED$D$IEĉ$ME;EM}:AAEA}GEĀ80D$]Uĉ$胏P+MMЍE$M9A]+AE1k{ [}t ]<{tl<}v<]qM̍ D$lID$P$L$ 艑{t }{Kvt}ȃEU}̍ D$ID$P$|$ 0dUBD$B$MA8Y$]fC?}EED$JD$PD$ $蜐UE8)ЃE<]B<:[UD$ D$LJD$PT$$6j]̍ D$QID$P$\$ @UЍ D$JD$P$T$ 'U@af`ً]fC }QDPu>}]EfUMBR)E1E1 D$ID$P$-aMAEAAEAuڀ}]uԋEԋM̍E$Wt:}UGE1; D$LD$P$觎E뽍'U8}} u]<$肍$GƋEt'D$$`蟋u4$Q]u}]Ívǀ<$ƃ E$tWUt u 4$$ߋE냋U D$ D$D$I$ڎ빋EUE1HUWVS,=e] tO<%tg<\uOC]UߋE؃|$$ ڋ|$$%‹SݤL$@LED$D$0E$%ME\$D$J<$趌1ED$D$0U$ED$D$0뜍ED$D$0ɍED$D$0wED$ED$0$荇E\$D$J<$UED$D$0$OwED$D$ 0?ED$D$ 0UED$D$ $+ED$J<$D$蔋ED$ED$ $ņED$D$ U$衆ED$J<$D$2ED$D$ E$cED$D$E$?gE\|$$KUED$D$$)ED$D$ 7ED$D$0ED$D$ MED$D$]USӃ$D$f諆fD$eefefe fef%eefefefe fe$fe(fe,fe0fe4fe8feD$$ƈ[]D$fD$$裈[]ÍUD$]}} u$@M膄1ơeD$E$ E|$$D$y~YD8ut$]u}]fe$ D$Wڸ?뿻tv말U$^u1À8t$fÉ'U1҉IMSt؃[]1ҸNMu$̅tՋXt΀;ftlj$袇뻐UMb}} ]]uuM})؋]E)ȋu}i+U]ÍvU$]t$Eu U)Q)$$$5TM$t$] UE]Ð&US$]ED$$σEU؉S$[]U]Ít&'UWVS^U諁E)E}Ut+1ƍED$E D$E$9}u߃[^_]Ë$ÐUS c ct Ћu[]US[(U蠆Y[out of memoryunknown erroris unknownis ambiguousrequires parameteris badly used here#%%-%ds %%5.1f%%%% %scurl: Warning: wbFailed to create the file %s wtFailed to open %s! singlecwdnocwdmulticwd%d - %dbad range input rb%s&%s;autolist%255[^=]=out of memory %127[^/]/%127[^;, ]filename=Error building form post! curl_formadd failed! ;type=%lld-hostproxyProtocols: Features: Failed to read %s.curlrc%s%s%s%s:%d: warning: '%s' %s %02d:%02d:%02d.%06d %s%s <= Recv SSL data<= Send SSL data%s== Info: %s=> Send header=> Send data<= Recv header<= Recv data%s%s, %zd bytes (0x%zx) %04zx: %02x option %s: %s --urlno URL specified! CURL_CA_BUNDLESSL_CERT_DIRSSL_CERT_FILEBuild-time engines: %s bad output glob! Error creating directory %s. abCan't open '%s'! %s/%shttps:// [%d/%d]: %s --> %s --_curl_--%s%s %s%c%s%s/?%sCOLUMNShttpThrowing away %lld bytes curl: (%d) %s http://HTTP errorFTP errorAsynchDNSDebugGSS-NegotiateIDNIPv6LargefileNTLMSPNEGOSSLSSPIkrb4libzCharConv**arandom-file*begd-file*cconnect-timeoutciphers*edisable-epsv*gtrace*htrace-ascii*ilimit-rate*jcompressed*k*lnegotiate*m*n*o*qftp-create-dirs*r*smax-redirs*tproxy-ntlm*ucrlf*vstderr*winterface*x*ymax-filesize*zdisable-eprt$aftp-ssl$bftp-pasv$csocks5socks$dtcp-nodelay$eproxy-digest$fproxy-basic$gretry$hretry-delay$iretry-max-time$j3p-url$k3p-user$l3p-quote$mftp-account$nproxy-anyauth$otrace-time$pignore-content-length$qftp-skip-pasv-ip$rftp-method$slocal-port$tsocks4$uftp-alternative-to-user$vftp-ssl-reqdhttp1.0tlsv1sslv2sslv3ipv4ipv6appendAuser-agentcookieBuse-asciicookie-jarCcontinue-atdadata-asciidbdata-binaryDdump-headerrefererEacacertEbcert-typeEckeyEdkey-typeEepassEfengineEgcapath failFformFsform-stringgloboffGgethelpHincludeheadjunk-session-cookiesinsecureKconfiglist-onlylocationLtlocation-trustedmanualnetrcnonetrc-optionalno-bufferoutputremote-nameproxytunnelPftpportftp-portdisableQrangeremote-timesilentshow-errortelnet-optionsTupload-fileUproxy-userverboseVversionwrite-outXhttp-requestYspeed-limitspeed-timetime-condprogress-bar<had unsupported trailing garbageexpected a proper numerical parameterthe installed libcurl version doesn't support thisEnter %s password for user '%s':curl: try 'curl --help' for more information You can only select one HTTP request! Usage: curl [options...] unsupported rate unit. Use G, M, K or B! unrecognized ftp file method '%s', using default Couldn't read data from file "%s", this makes an empty POST. Illegally formatted content-type field! curl_formadd failed, possibly the file %s is bad! Illegally formatted input field! error trying read config from the '%s' file built-in manual was disabled at build-time! A specfied range MUST include at least one dash (-). Appending one for you! curl 7.15.5 (i686-redhat-linux-gnu) %s Illegal date format for -z/--timecond (and not a file name). Disabling time condition. See curl_getdate(3) for valid date syntax. error initializing curl library curl/7.15.5 (i686-redhat-linux-gnu) %sRemote file name has no length! You don't have permission to create %s. The directory name %s is too long. %s resides on a read-only file system. No space left on the file system that will contain the directory %s. Cannot create directory %s because you exceeded your quota. If this HTTPS server uses a certificate signed by a CA represented in the bundle, the certificate verification probably failed due to a problem with the certificate (it might be expired, or the name might not match the domain name in the URL). If you'd like to turn off curl's verification of the certificate, use the -k (or --insecure) option. More details here: http://curl.haxx.se/docs/sslcerts.html curl performs SSL certificate verification by default, using a "bundle" of Certificate Authority (CA) public keys (CA certs). The default bundle is named curl-ca-bundle.crt; you can specify an alternate file using the --cacert option. Transient problem: %s Will retry in %ld seconds. %ld retries left. Options: (H) means HTTP/HTTPS only, (F) means FTP only -a/--append Append to target file when uploading (F) -A/--user-agent User-Agent to send to server (H) --anyauth Pick "any" authentication method (H) -b/--cookie Cookie string or file to read cookies from (H) --basic Use HTTP Basic Authentication (H) -B/--use-ascii Use ASCII/text transfer -c/--cookie-jar Write cookies to this file after operation (H) -C/--continue-at Resumed transfer offset -d/--data HTTP POST data (H) --data-ascii HTTP POST ASCII data (H) --data-binary HTTP POST binary data (H) --negotiate Use HTTP Negotiate Authentication (H) --digest Use HTTP Digest Authentication (H) --disable-eprt Inhibit using EPRT or LPRT (F) --disable-epsv Inhibit using EPSV (F) -D/--dump-header Write the headers to this file --egd-file EGD socket path for random data (SSL) --tcp-nodelay Use the TCP_NODELAY option -e/--referer Referer URL (H) -E/--cert Client certificate file and password (SSL) --cert-type Certificate file type (DER/PEM/ENG) (SSL) --key Private key file name (SSL) --key-type Private key file type (DER/PEM/ENG) (SSL) --pass Pass phrase for the private key (SSL) --engine Crypto engine to use (SSL). "--engine list" for list --cacert CA certificate to verify peer against (SSL) --capath CA directory (made using c_rehash) to verify peer against (SSL) --ciphers SSL ciphers to use (SSL) --compressed Request compressed response (using deflate or gzip) --connect-timeout Maximum time allowed for connection --create-dirs Create necessary local directory hierarchy --crlf Convert LF to CRLF in upload -f/--fail Fail silently (no output at all) on HTTP errors (H) --ftp-account Account data to send when requested by server (F) --ftp-alternative-to-user String to replace "USER [name]" (F) --ftp-create-dirs Create the remote dirs if not present (F) --ftp-method [multicwd/nocwd/singlecwd] Control CWD usage (F) --ftp-pasv Use PASV/EPSV instead of PORT (F) --ftp-skip-pasv-ip Skip the IP address for PASV (F) --ftp-ssl Try SSL/TLS for the ftp transfer (F) --ftp-ssl-reqd Require SSL/TLS for the ftp transfer (F) -F/--form Specify HTTP multipart POST data (H) --form-string Specify HTTP multipart POST data (H) -g/--globoff Disable URL sequences and ranges using {} and [] -G/--get Send the -d data with a HTTP GET (H) -h/--help This help text -H/--header Custom header to pass to server (H) --ignore-content-length Ignore the HTTP Content-Length header -i/--include Include protocol headers in the output (H/F) -I/--head Show document info only -j/--junk-session-cookies Ignore session cookies read from file (H) --interface Specify network interface/address to use --krb4 Enable krb4 with specified security level (F) -k/--insecure Allow connections to SSL sites without certs (H) -K/--config Specify which config file to read -l/--list-only List only names of an FTP directory (F) --limit-rate Limit transfer speed to this rate --local-port [-num] Force use of these local port numbers -L/--location Follow Location: hints (H) --location-trusted Follow Location: and send authentication even to other hostnames (H) -m/--max-time Maximum time allowed for the transfer --max-redirs Maximum number of redirects allowed (H) --max-filesize Maximum file size to download (H/F) -M/--manual Display the full manual -n/--netrc Must read .netrc for user name and password --netrc-optional Use either .netrc or URL; overrides -n --ntlm Use HTTP NTLM authentication (H) -N/--no-buffer Disable buffering of the output stream -o/--output Write output to instead of stdout -O/--remote-name Write output to a file named as the remote file -p/--proxytunnel Operate through a HTTP proxy tunnel (using CONNECT) --proxy-anyauth Pick "any" proxy authentication method (H) --proxy-basic Use Basic authentication on the proxy (H) --proxy-digest Use Digest authentication on the proxy (H) --proxy-ntlm Use NTLM authentication on the proxy (H) -P/--ftp-port
Use PORT with address instead of PASV (F) -q If used as the first parameter disables .curlrc -Q/--quote Send command(s) to server before file transfer (F) -r/--range Retrieve a byte range from a HTTP/1.1 or FTP server --random-file File for reading random data from (SSL) -R/--remote-time Set the remote file's time on the local output --retry Retry request times if transient problems occur --retry-delay When retrying, wait this many seconds between each --retry-max-time Retry only within this period -s/--silent Silent mode. Don't output anything -S/--show-error Show error. With -s, make curl show errors when they occur --socks4 Use SOCKS4 proxy on given host + port --socks5 Use SOCKS5 proxy on given host + port --stderr Where to redirect stderr. - means stdout -t/--telnet-option Set telnet option --trace Write a debug trace to the given file --trace-ascii Like --trace but without the hex output --trace-time Add time stamps to trace/verbose output -T/--upload-file Transfer to remote site --url Spet URL to work with -u/--user Set server user and password -U/--proxy-user Set proxy user and password -v/--verbose Make the operation more talkative -V/--version Show version number and quit -w/--write-out [format] What to output after completion -x/--proxy Use HTTP proxy on given port -X/--request Specify request command to use -y/--speed-time Time needed to trig speed-limit abort. Defaults to 30 -Y/--speed-limit Stop transfer if below speed-limit for 'speed-time' secs -z/--time-cond

:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ Read-Only ]

:: Make Dir ::
 
[ Read-Only ]
:: Make File ::
 
[ Read-Only ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0059 ]--