!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/usr/share/doc/selinux-policy-2.4.6/html/   drwxr-xr-x
Free 50.94 GB of 127.8 GB (39.85%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     global_tunables.html (41.46 KB)      -rw-r--r--
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
Security Enhanced Linux Reference Policy

Global tunables:

allow_console_login
Default value

false

Description

Allow users to connect to console (s390)

allow_cvs_read_shadow
Default value

false

Description

Allow cvs daemon to read shadow

allow_execheap
Default value

false

Description

Allow making the heap executable.

allow_execmem
Default value

false

Description

Allow making anonymous memory executable, e.g. for runtime-code generation or executable stack.

allow_execmod
Default value

false

Description

Allow making a modified private file mapping executable (text relocation).

allow_execstack
Default value

false

Description

Allow making the stack executable via mprotect. Also requires allow_execmem.

allow_ftpd_anon_write
Default value

false

Description

Allow ftp servers to modify public files used for public file transfer services.

allow_ftpd_full_access
Default value

false

Description

Allow ftp servers to login to local users and read/write all files on the system, governed by DAC.

allow_ftpd_use_cifs
Default value

false

Description

Allow ftp servers to use cifs used for public file transfer services.

allow_ftpd_use_nfs
Default value

false

Description

Allow ftp servers to use nfs used for public file transfer services.

allow_gpg_execstack
Default value

false

Description

Allow gpg executable stack

allow_gssd_read_tmp
Default value

true

Description

Allow gssd to read temp directory.

allow_httpd_anon_write
Default value

false

Description

Allow Apache to modify public files used for public file transfer services.

allow_httpd_mod_auth_pam
Default value

false

Description

Allow Apache to use mod_auth_pam

allow_ipsec_label
Default value

true

Description

Allow all domains to use ipsec labeled packets

allow_kerberos
Default value

false

Description

Allow system to run with kerberos

allow_mount_anyfile
Default value

false

Description

Allow mount to mount any file

allow_mounton_anydir
Default value

true

Description

Allow mount to mount any dir

allow_mplayer_execstack
Default value

false

Description

Allow mplayer executable stack

allow_netlabel
Default value

true

Description

Allow all domains to use netlabel labeled packets

allow_nfsd_anon_write
Default value

false

Description

Allow nfs servers to modify public files used for public file transfer services.

allow_polyinstantiation
Default value

false

Description

Enable polyinstantiated directory support.

allow_ptrace
Default value

false

Description

Allow sysadm to ptrace all processes

allow_rsync_anon_write
Default value

false

Description

Allow rsync to modify public files used for public file transfer services.

allow_saslauthd_read_shadow
Default value

false

Description

Allow sasl to read shadow

allow_smbd_anon_write
Default value

false

Description

Allow samba to modify public files used for public file transfer services.

allow_ssh_keysign
Default value

false

Description

allow host key based authentication

allow_unconfined_execmem_dyntrans
Default value

false

Description

Allow unconfined to dyntrans to unconfined_execmem

allow_unlabeled_packets
Default value

true

Description

Allow unlabeled packets to work on system

allow_user_mysql_connect
Default value

false

Description

Allow users to connect to mysql

allow_write_xshm
Default value

false

Description

Allows clients to write to the X server shared memory segments.

allow_ypbind
Default value

false

Description

Allow system to run with NIS

allow_zebra_write_config
Default value

false

Description

Allow zebra daemon to write it configuration files

cdrecord_read_content
Default value

false

Description

Allow cdrecord to read various content. nfs, samba, removable devices, user temp and untrusted content files

cron_can_relabel
Default value

false

Description

Allow system cron jobs to relabel filesystem for restoring file contexts.

disable_evolution_trans
Default value

false

Description

Disable transitions to evolution domains.

disable_games_trans
Default value

false

Description

force to games to run in user_t mapping executable (text relocation).

disable_mozilla_trans
Default value

false

Description

Disable transitions to user mozilla domains

disable_thunderbird_trans
Default value

false

Description

Disable transitions to user thunderbird domains

fcron_crond
Default value

false

Description

Enable extra rules in the cron domain to support fcron.

ftp_home_dir
Default value

false

Description

Allow ftp to read and write files in the user home directories

ftpd_is_daemon
Default value

false

Description

Allow ftpd to run directly without inetd

global_ssp
Default value

false

Description

Enable reading of urandom for all domains.

This should be enabled when all programs are compiled with ProPolice/SSP stack smashing protection. All domains will be allowed to read from /dev/urandom.

httpd_builtin_scripting
Default value

false

Description

Allow httpd to use built in scripting (usually php)

httpd_can_network_connect
Default value

false

Description

Allow http daemon to tcp connect

httpd_can_network_connect_db
Default value

false

Description

Allow httpd to connect to mysql/posgresql

httpd_can_network_relay
Default value

false

Description

Allow httpd to act as a relay

httpd_enable_cgi
Default value

false

Description

Allow httpd cgi support

httpd_enable_ftp_server
Default value

false

Description

Allow httpd to act as a FTP server by listening on the ftp port.

httpd_enable_homedirs
Default value

false

Description

Allow httpd to read home directories

httpd_ssi_exec
Default value

false

Description

Run SSI execs in system CGI script domain.

httpd_tty_comm
Default value

false

Description

Allow http daemon to communicate with the TTY

httpd_unified
Default value

false

Description

Run CGI in the main httpd domain

mail_read_content
Default value

false

Description

Allow email client to various content. nfs, samba, removable devices, user temp and untrusted content files

mozilla_read_content
Default value

false

Description

Control mozilla content access

named_write_master_zones
Default value

false

Description

Allow BIND to write the master zone files. Generally this is used for dynamic DNS.

nfs_export_all_ro
Default value

false

Description

Allow nfs to be exported read only

nfs_export_all_rw
Default value

false

Description

Allow nfs to be exported read/write.

pppd_can_insmod
Default value

false

Description

Allow pppd to load kernel modules for certain modems

pppd_for_user
Default value

false

Description

Allow pppd to be run for a regular user

read_default_t
Default value

false

Description

Allow reading of default_t files.

read_untrusted_content
Default value

false

Description

Allow applications to read untrusted content If this is disallowed, Internet content has to be manually relabeled for read access to be granted

run_ssh_inetd
Default value

false

Description

Allow ssh to run from inetd instead of as a daemon.

samba_domain_controller
Default value

false

Description

Allow samba to run as the domain controller; add machines to passwd file

samba_enable_home_dirs
Default value

false

Description

Allow samba to export user home directories.

samba_export_all_ro
Default value

false

Description

Allow samba to be exported read only

samba_export_all_rw
Default value

false

Description

Allow samba to be exported read/write.

samba_share_nfs
Default value

false

Description

Allow samba to export NFS volumes.

squid_connect_any
Default value

false

Description

Allow squid to connect to all ports, not just HTTP, FTP, and Gopher ports.

ssh_sysadm_login
Default value

false

Description

Allow ssh logins as sysadm_r:sysadm_t

staff_read_sysadm_file
Default value

false

Description

Allow staff_r users to search the sysadm home dir and read files (such as ~/.bashrc)

stunnel_is_daemon
Default value

false

Description

Configure stunnel to be a standalone daemon or inetd service.

use_lpd_server
Default value

false

Description

Use lpd server instead of cups

use_nfs_home_dirs
Default value

false

Description

Support NFS home directories

use_samba_home_dirs
Default value

false

Description

Support SAMBA home directories

user_direct_mouse
Default value

false

Description

Allow regular users direct mouse access

user_dmesg
Default value

false

Description

Allow users to read system messages.

user_net_control
Default value

false

Description

Allow users to control network interfaces (also needs USERCTL=true)

user_ping
Default value

false

Description

Control users use of ping and traceroute

user_rw_noexattrfile
Default value

false

Description

Allow user to r/w files on filesystems that do not have extended attributes (FAT, CDROM, FLOPPY)

user_tcp_server
Default value

false

Description

Allow users to run TCP servers (bind to ports and accept connection from the same domain and outside users) disabling this forces FTP passive mode and may change other protocols.

user_ttyfile_stat
Default value

false

Description

Allow w to display everyone

virt_use_nfs
Default value

false

Description

Allow virt to manage nfs files

virt_use_samba
Default value

false

Description

Allow virt to manage cifs files

write_untrusted_content
Default value

false

Description

Allow applications to write untrusted content If this is disallowed, no Internet content will be stored.

xdm_sysadm_login
Default value

false

Description

Allow xdm logins as sysadm


:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ Read-Only ]

:: Make Dir ::
 
[ Read-Only ]
:: Make File ::
 
[ Read-Only ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.012 ]--