!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/usr/bin/   drwxr-xr-x
Free 52.28 GB of 127.8 GB (40.9%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     mysqlshow (22.5 KB)      -rwxr-xr-x
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
ELF04(U4 (444444h?h?@@HHH  Ptd =  ttQtd/lib/ld-linux.so.2GNU	3!O
P3568;<>?ACDk|QrqX%ڬK|k	C8CE
2b:Yc#)"Iu'
 % v?$( X,$K?dE~
9jHPD*d#';/_C(Z_5DEX3#I62(xeB

qqHXHlK(jHЯ
0
i
 MxM[M[dQMM8M1(LMʄM:Mq5.McKMA&M?6M'G6GMWf7VMhP1aMuMK:M쌌iM84HH| HHЏ菎QQ`0^^^^^_4_8_<_L_____̿п0ԿؿܿٳP>h><Џoo12 5Ssii
ti	ii
L2P2H8<6DC,048<@DH	L
PTX
\`dhlptx| !"#$%&'()*+,-./01UI;#5$%(%,h%0h%4h%8h%<h %@h(%Dh0%Hh8p%Lh@`%PhHP%ThP@%XhX0%\h` %`hh%dhp%hhx%lh%ph%th%xh%|h%h%h%hp%h`%hP%h@%h0%h %h%h%h%h%h%h%h%h %h(%h0%h8p%h@`%hHP%hP@%hX0%h` %hh%hp%hx1^PTRhЯhQVhUS[0tX[ÐUS=u?-X9v&9w[]Ít&'Utt	$ÐU(D$D$D$D$D$D$$UÍt&'USE]p(IV?v1[]f=#=+uD$D$$uá\$D$̳D$$d$tq$7D$$G;t؍vx8u;tC
1[]=v/f!
1[]$sv$$$D$$D$$ D$ $$@$@E$kt&UWVS1ۃ$|D$D$4$d"T$D$D$İ$ 4$9s4$lҋ@ u빡$
D$&[^_]ÍUWVS$+D$D$<$<$taf$nS 9wkЃt$1ۍpv$-D$9u$+D$<$u$
D$d[^_]ÉC 
USÃ"D$$
$|D$$D$B D$İ$D$$uΡ$
D$[]&UWVS<eE1D$D$T$D$˰$]t	>S\$<$<$D$$D$tt$D$$$
D$	‰!$Au$~1ҍt&ЋUe3<[^_]Ív<$`D$t$D$lD$T$D$$<$X=(uD$bD$$D$WUD$D$t$D$$Rf3t&'UWVSE,E$+D$Eƃt1ۡ$-D$9u$+D$gUBE
tBEB묡$
D$8UU$|D$EUEU܋E܉$9Es}U)ƃt1ۡ$ D$9ut!1ۡU܉D$$9uE))t1ۡ$ D$y9u$|D$`UBEEtBERU,$
D$(UU$+D$
Efƃt%1ۍ&$-D$9u$+D$UBEtBEB륡$
D$,[^_]Ð&UVS ]uEE$|D$_$ D$J$D$y$9r!Ív$ D$9sUBEtBEr{$|D$$
D$ [^]ÍUVSE E$+D$Eƃt1ې$-D$p9u$+D$WUBEu$
D$3 [^]Ít&UWVSˁT$eE1$1t$uv\$t$D$$l=ut$D$D$D$$T$$$uD$$D$t\$D$$$
D$$
x s=LD$ D$
D$ND$D$FD$
D$4|$$?7=D$D$&D$$i$D$D$T$D$D$$bUe3jĜ[^_]Ë$D$(D$T$D$D$$$nD$D$
D$ND$D$F|$$?nDžifED$ED$ D$
D$D$D$
F|$D$$G&$#=g*6ED$ED$D$
D$D$|$$xD$D$
D$4|$$?FD$|$$?)t&D$$@D$D$$$JD$]D$D$D$E$c$+=$D$aD$D$D$"D$$j$Džt8$\D$D$
D$$j$|D${T$ED$@D$$fED$Y$ED$Y$t&D$|$$ut&D$D$
FD$|$$F=

D$T$L$D$<$t?t5vD$D$$T$?$11}ED$D$D$D$
FED$D$
v21,D$D$Q10҅0Ʌu1D$D$D$FD$
D$4|$$?jD$D$D$F|$$?=L$qUWVSQAeU1ҍ\$t$D$ $\D$`D$@\$4$P=
=1DžTM"&<%t.<*t+<?m~<\s<_uڃuՄ><$J==SD$D$<$,D$<$D$ۋ
D$D$L$T$D$<$D$D$<$2D$D$D$D$$$Lt&Kbv__va%%z$$D$D$	<$<$D$D$D$D$D$sD$D$<$kI1ۃ>uL@
D$D$D$$|$ Dž$	ƅ19=t7p<$D$=t$D$D$D$$LT$<$I<$7$D$D$
D$$$D$ȷ$t$$D$$t/:t$D$D$T$D$$}L$<$S<$At$D$$T$=Tt8^$
D$	‰:$Zu=$D$5t$$D$$L$<$x<$f$	
‰$u$$1t&<$L$F^DžtC$Dž	^D$$D$q$p 	s	ZD$D$D$ND$D$?t$$DZDžt(Dž?D$t$$$nAt<$D$D$<$<$6	.<$$D$ѱD$AD$D$E$]=KDž$$D$aD$D$D$L$<$Ru<$t$XD$D$
D$$f$x]D$t$$DZN=tI1É<$Yt$$,$d1D$D$D$?t$$DZ6<$t$D$L$D$D$D$$$>P4$D$D$L$t?t5vD$D$$D$1ۉ$<$t$D$D$D$D$"<$D$lD$L$D$D$$9<$mD$LD$D$D$$MD$D$ܱD$AD$$3D$D$jD$AD$$${jMD$D$D$D$L$t$$,UD$Y$jD$Y$zH$L$$HD$Pg$=1<$t$D$$D$D$D$D$)$L$D$D$$c$FbQD$ֱT$CED$D$D$t$$:00f1U]Ít&'UWVS^5E)E}Ut+1ƍED$ED$E$9}u߃[^_]Ë$ÐUStЋu[]US[ÜY[i686redhat-linux-gnu5.0.779.5my %-*s|show table status from ` like 'Database: %s  Wildcard: %s fullshow%s tables like '%s'show%s tablestable_typeTablesColumnsTotal RowsN/A%8uSELECT COUNT(*) FROM `%s`%10lu%10d%u row%s in set.

%s: Too many arguments
%s: %s
Wildcard: %s
Databases%6lu%12lu%6d%12d%u row%s in set.
select count(*) from `%s`Database: %s  Table: %s  Rows: %lushow keys from `Table has no keysmysqlshowclientlatin1character-sets-dirdefault-character-setcountcompressdebughelpDisplay this help and exit.hostConnect to host.statusShow keys for table.passwordportprotocolshow-table-typeShow table type column.socketsslssl-cassl-capathssl-certssl-cipherssl-keyssl-verify-server-certuserverboseversion%s  Ver %s Distrib %s, for %s (%s)
Unknown option to protocol: %s
Copyright (C) 2000-2006 MySQL ABThis software comes with ABSOLUTELY NO WARRANTY. This is free software,
and you are welcome to modify and redistribute it under the GPL license
Shows the structure of a mysql database (databases,tables and columns)
Usage: %s [OPTIONS] [database [table [column]]]

If last argument contains a shell or SQL wildcard (*,?,% or _) then only
what's matched by the wildcard is shown.
If no database is given then all matching databases are shown.
If no table is given then all matching tables in database are shown
If no column is given then all matching columns and columntypes in table
are shown%s: Cannot get status for db: %s, table: %s: %s
This error probably means that your MySQL server doesn't support the
'show table status' command.
%s: Cannot connect to db %s: %s
%s: Cannot list tables in %s: %s
%s: Cannot list databases: %s
%s: Cannot connect to db: %s: %s
%s: Cannot get record count for db: %s, table: %s: %s
show /*!32332 FULL */ columns from `%s: Cannot list columns in db: %s, table: %s: %s
%s: Cannot list keys in db: %s, table: %s: %s
Directory where character sets are.Set the default character set.Show number of rows per table (may be slow for not MyISAM tables)Use compression in server/client protocol.Output debug log. Often this is 'd:t:o,filename'.Shows a lot of extra information about each table.Password to use when connecting to server. If password is not given it's asked from the tty.Port number to use for connection or 0 for default to, in order of preference, my.cnf, $MYSQL_TCP_PORT, /etc/services, built-in default (3306).The protocol of connection (tcp,socket,pipe,memory).Socket file to use for connection.Enable SSL for connection (automatically enabled with other flags). Disable with --skip-ssl.CA file in PEM format (check OpenSSL docs, implies --ssl).CA directory (check OpenSSL docs, implies --ssl).X509 cert in PEM format (implies --ssl).SSL cipher to use (implies --ssl).X509 key in PEM format (implies --ssl).Verify server's "Common Name" in its cert against hostname used when connecting. This option is disabled by default.User for login if not current user.More verbose output; You can use this multiple times to get even more verbose output.Output version information and exit.;p
@@@``$|EAB
0`AB
D L0AB
ACCpГAB
AGAB
A 0AB
ACI 8AB
I`AB
E0AB
H0AB
C,PB
D	FAB
BDzR|AB
8iAB
Cx}
xoh
 @@oooVodo|oo.ɲTXPWЙ 0Xp2)PA| `BX`rв0Zp޲UP=p@XbipcT	x,,	=Cܸ#	?ϲhԲ	i<Skpp	
Pй+`	t(@S	GK!	R"X	] 	f#	qܻ	yEu|	vV!NN@``` l  `e,dlibmysqlclient.so.15__gmon_start___Jv_RegisterClassesmysql_list_tablesmysql_list_dbsmy_strdupmysql_fetch_fieldmy_initmysql_num_rowsmysql_optionsmysql_list_fieldsmysql_select_dbmysql_fetch_rowmy_prognamemysql_initstrmovget_tty_passwordmysql_errnomysql_real_connectmysql_errormy_snprintfmysql_free_resultmysql_store_resultmysql_real_escape_stringsql_protocol_typelibmysql_querymysql_field_seekfind_typeload_defaultshandle_optionsprint_defaultsmysql_closemysql_ssl_setcharsets_dirmy_print_variablesmy_no_flags_freemysql_num_fieldsmysql_affected_rowsmy_endstrxmovmy_charset_latin1my_print_helplibcrypt.so.1libnsl.so.1libm.so.6libssl.so.6libcrypto.so.6libz.so.1libc.so.6_IO_stdin_used__printf_chkexit_IO_putc__stack_chk_failstrlen__fprintf_chkstdoutfputsstderrfwrite__sprintf_chk__strtoull_internal__libc_start_main_edata__bss_start/usr/lib/mysql__libc_csu_fini_fp_hw__data_start__libc_csu_initlibmysqlclient_15GLIBC_2.4GLIBC_2.3.4GLIBC_2.0/lib/ld-linux.so.2libgssapi_krb5.so.2libkrb5.so.3libcom_err.so.2libk5crypto.so.3libresolv.so.2libdl.so.2libkrb5support.so.0libkeyutils.so.1libselinux.so.1libsepol.so.1mysqlshow.debugEwELF04<J4 (444444h?h?@H	
@HHH  Ptd =  ttQtd44HH !ohh+P3dd;oVV
Ho
`W	@@@`	i
d
o00H uxx0{0  =t=@@@@A  ABH HHIHI\I.shstrtab.interp.note.ABI-tag.gnu.hash.dynsym.dynstr.gnu.version.gnu.version_r.rel.dyn.rel.plt.init.text.fini.rodata.eh_frame_hdr.eh_frame.ctors.dtors.jcr.dynamic.got.got.plt.data.bss.gnu_debuglink.dynbss.gnu.liblist.gnu.conflict.gnu.prelink_undo44HH !ohh+Podd|;oVV
Ho
`W	@@@`	i
d
o00H uxx0{0  =t=@@@@A  ABH HHIIH3JNNDT

:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ Read-Only ]

:: Make Dir ::
 
[ Read-Only ]
:: Make File ::
 
[ Read-Only ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.006 ]--