!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/var/www/html/alumni/inc/fckeditor/editor/plugins/placeholder/   drwxr-xr-x
Free 53.7 GB of 127.8 GB (42.02%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     fckplugin.js (5.47 KB)      -rw-r--r--
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
/*

 * FCKeditor - The text editor for Internet - http://www.fckeditor.net

 * Copyright (C) 2003-2007 Frederico Caldeira Knabben

 *

 * == BEGIN LICENSE ==

 *

 * Licensed under the terms of any of the following licenses at your

 * choice:

 *

 *  - GNU General Public License Version 2 or later (the "GPL")

 *    http://www.gnu.org/licenses/gpl.html

 *

 *  - GNU Lesser General Public License Version 2.1 or later (the "LGPL")

 *    http://www.gnu.org/licenses/lgpl.html

 *

 *  - Mozilla Public License Version 1.1 or later (the "MPL")

 *    http://www.mozilla.org/MPL/MPL-1.1.html

 *

 * == END LICENSE ==

 *

 * Plugin to insert "Placeholders" in the editor.

 */



// Register the related command.

FCKCommands.RegisterCommand( 'Placeholder', new FCKDialogCommand( 'Placeholder', FCKLang.PlaceholderDlgTitle, FCKPlugins.Items['placeholder'].Path + 'fck_placeholder.html', 340, 170 ) ) ;



// Create the "Plaholder" toolbar button.

var oPlaceholderItem = new FCKToolbarButton( 'Placeholder', FCKLang.PlaceholderBtn ) ;

oPlaceholderItem.IconPath = FCKPlugins.Items['placeholder'].Path + 'placeholder.gif' ;



FCKToolbarItems.RegisterItem( 'Placeholder', oPlaceholderItem ) ;





// The object used for all Placeholder operations.

var FCKPlaceholders = new Object() ;



// Add a new placeholder at the actual selection.

FCKPlaceholders.Add = function( name )

{

	var oSpan = FCK.InsertElement( 'span' ) ;

	this.SetupSpan( oSpan, name ) ;

}



FCKPlaceholders.SetupSpan = function( span, name )

{

	span.innerHTML = '[[ ' + name + ' ]]' ;



	span.style.backgroundColor = '#ffff00' ;

	span.style.color = '#000000' ;



	if ( FCKBrowserInfo.IsGecko )

		span.style.cursor = 'default' ;



	span._fckplaceholder = name ;

	span.contentEditable = false ;



	// To avoid it to be resized.

	span.onresizestart = function()

	{

		FCK.EditorWindow.event.returnValue = false ;

		return false ;

	}

}



// On Gecko we must do this trick so the user select all the SPAN when clicking on it.

FCKPlaceholders._SetupClickListener = function()

{

	FCKPlaceholders._ClickListener = function( e )

	{

		if ( e.target.tagName == 'SPAN' && e.target._fckplaceholder )

			FCKSelection.SelectNode( e.target ) ;

	}



	FCK.EditorDocument.addEventListener( 'click', FCKPlaceholders._ClickListener, true ) ;

}



// Open the Placeholder dialog on double click.

FCKPlaceholders.OnDoubleClick = function( span )

{

	if ( span.tagName == 'SPAN' && span._fckplaceholder )

		FCKCommands.GetCommand( 'Placeholder' ).Execute() ;

}



FCK.RegisterDoubleClickHandler( FCKPlaceholders.OnDoubleClick, 'SPAN' ) ;



// Check if a Placholder name is already in use.

FCKPlaceholders.Exist = function( name )

{

	var aSpans = FCK.EditorDocument.getElementsByTagName( 'SPAN' ) ;



	for ( var i = 0 ; i < aSpans.length ; i++ )

	{

		if ( aSpans[i]._fckplaceholder == name )

			return true ;

	}



	return false ;

}



if ( FCKBrowserInfo.IsIE )

{

	FCKPlaceholders.Redraw = function()

	{

		if ( FCK.EditMode != FCK_EDITMODE_WYSIWYG )

			return ;



		var aPlaholders = FCK.EditorDocument.body.innerText.match( /\[\[[^\[\]]+\]\]/g ) ;

		if ( !aPlaholders )

			return ;



		var oRange = FCK.EditorDocument.body.createTextRange() ;



		for ( var i = 0 ; i < aPlaholders.length ; i++ )

		{

			if ( oRange.findText( aPlaholders[i] ) )

			{

				var sName = aPlaholders[i].match( /\[\[\s*([^\]]*?)\s*\]\]/ )[1] ;

				oRange.pasteHTML( '<span style="color: #000000; background-color: #ffff00" contenteditable="false" _fckplaceholder="' + sName + '">' + aPlaholders[i] + '</span>' ) ;

			}

		}

	}

}

else

{

	FCKPlaceholders.Redraw = function()

	{

		if ( FCK.EditMode != FCK_EDITMODE_WYSIWYG )

			return ;



		var oInteractor = FCK.EditorDocument.createTreeWalker( FCK.EditorDocument.body, NodeFilter.SHOW_TEXT, FCKPlaceholders._AcceptNode, true ) ;



		var	aNodes = new Array() ;



		while ( ( oNode = oInteractor.nextNode() ) )

		{

			aNodes[ aNodes.length ] = oNode ;

		}



		for ( var n = 0 ; n < aNodes.length ; n++ )

		{

			var aPieces = aNodes[n].nodeValue.split( /(\[\[[^\[\]]+\]\])/g ) ;



			for ( var i = 0 ; i < aPieces.length ; i++ )

			{

				if ( aPieces[i].length > 0 )

				{

					if ( aPieces[i].indexOf( '[[' ) == 0 )

					{

						var sName = aPieces[i].match( /\[\[\s*([^\]]*?)\s*\]\]/ )[1] ;



						var oSpan = FCK.EditorDocument.createElement( 'span' ) ;

						FCKPlaceholders.SetupSpan( oSpan, sName ) ;



						aNodes[n].parentNode.insertBefore( oSpan, aNodes[n] ) ;

					}

					else

						aNodes[n].parentNode.insertBefore( FCK.EditorDocument.createTextNode( aPieces[i] ) , aNodes[n] ) ;

				}

			}



			aNodes[n].parentNode.removeChild( aNodes[n] ) ;

		}



		FCKPlaceholders._SetupClickListener() ;

	}



	FCKPlaceholders._AcceptNode = function( node )

	{

		if ( /\[\[[^\[\]]+\]\]/.test( node.nodeValue ) )

			return NodeFilter.FILTER_ACCEPT ;

		else

			return NodeFilter.FILTER_SKIP ;

	}

}



FCK.Events.AttachEvent( 'OnAfterSetHTML', FCKPlaceholders.Redraw ) ;



// We must process the SPAN tags to replace then with the real resulting value of the placeholder.

FCKXHtml.TagProcessors['span'] = function( node, htmlNode )

{

	if ( htmlNode._fckplaceholder )

		node = FCKXHtml.XML.createTextNode( '[[' + htmlNode._fckplaceholder + ']]' ) ;

	else

		FCKXHtml._AppendChildNodes( node, htmlNode, false ) ;



	return node ;

}

:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ ok ]

:: Make Dir ::
 
[ ok ]
:: Make File ::
 
[ ok ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0149 ]--