!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/usr/share/doc/cyrus-sasl-lib-2.1.22/   drwxr-xr-x
Free 50.94 GB of 127.8 GB (39.86%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     mechanisms.html (6.95 KB)      -rw-r--r--
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
SASL Mechanism Properties/Features

SASL Mechanism Properties/Features

This table shows what security flags and features are supported by each of the mechanisms provided by the Cyrus SASL Library.


MAX
SSF
SECURITY PROPERTIES FEATURES
NOPLAIN
NOACTIVE
NODICT
FORWARD
NOANON
CRED
MUTUAL
CLT FIRST
SRV FIRST
SRV LAST
PROXY
ANONYMOUS
0
X






X



CRAM-MD5
0
X



X



X


DIGEST-MD5
128
X



X

X
reauth
initial auth
X
X
EXTERNAL
0
X

X

X


X


X
GSSAPI
56
X
X


X

X
X


X
KERBEROS_V4
56
X
X


X

X

X

X
LOGIN
0




X



X


NTLM
0
X



X


X



OTP
0
X


X
X


X


X
PLAIN
0




X


X


X
SRP
128
X
X
X
X
X

X
X

X
X

Understanding this table:

  • MAX SSF - The maximum Security Strength Factor supported by the mechanism (roughly the number of bits of encryption provided, but may have other meanings, for example an SSF of 1 indicates integrity protection only, no encryption).
  • NOPLAIN - Mechanism is not susceptable to simple passive (eavesdropping) attack.
  • NOACTIVE - Protection from active (non-dictionary) attacks during authentication exchange. (Implies MUTUAL).
  • NODICT - Not susceptable to passive dictionary attack.
  • NOFORWARD - Breaking one session won't help break the next.
  • NOANON - Don't permit anonymous logins.
  • CRED - Mechanism can pass client credentials.
  • MUTUAL - Supports mutual authentication (authenticates the server to the client)
  • CLTFIRST - The client should send first in this mechanism.
  • SRVFIRST - The server must send first in this mechanism.
  • SRVLAST - This mechanism supports server-send-last configurations.
  • PROXY - This mechanism supports proxy authentication.

:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ Read-Only ]

:: Make Dir ::
 
[ Read-Only ]
:: Make File ::
 
[ Read-Only ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0074 ]--