!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/var/www/html/alumni/inc/geshi/geshi/   drwxr-xr-x
Free 50.91 GB of 127.8 GB (39.84%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     xpp.php (8.27 KB)      -rw-r--r--
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
<?php
/*************************************************************************************
 * xpp.php
 * -------
 * Author: Simon Butcher (simon@butcher.name)
 * Copyright: (c) 2007 Simon Butcher (http://simon.butcher.name/)
 * Release Version: 1.0.7.19
 * CVS Revision Version: $Revision: 1.0 $
 * Date Started: 2007/02/27
 * Last Modified: $Date: 2007/02/28 00:00:00 $
 *
 * Axapta/Dynamics Ax X++ language file for GeSHi.
 * For details, see <http://msdn.microsoft.com/en-us/library/aa867122.aspx>
 *
 * CHANGES
 * -------
 * 2007/02/28 (1.0.0)
 *  -  First Release
 *
 * TODO (updated 2007/02/27)
 * -------------------------
 *
 *************************************************************************************
 *
 *     This file is part of GeSHi.
 *
 *   GeSHi is free software; you can redistribute it and/or modify
 *   it under the terms of the GNU General Public License as published by
 *   the Free Software Foundation; either version 2 of the License, or
 *   (at your option) any later version.
 *
 *   GeSHi is distributed in the hope that it will be useful,
 *   but WITHOUT ANY WARRANTY; without even the implied warranty of
 *   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 *   GNU General Public License for more details.
 *
 *   You should have received a copy of the GNU General Public License
 *   along with GeSHi; if not, write to the Free Software
 *   Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA  02111-1307  USA
 *
 ************************************************************************************/

$language_data = array (
    
'LANG_NAME' => 'X++',
    
'COMMENT_SINGLE' => array(=> '//'),
    
'COMMENT_MULTI' => array('/*' => '*/'),
    
'CASE_KEYWORDS' => GESHI_CAPS_NO_CHANGE,
    
'QUOTEMARKS' => array("'"'"'),
    
'ESCAPE_CHAR' => '\\',
    
'KEYWORDS' => array(
        
=> array( // Primitive types
            
'void',
            
'str',
            
'real',
            
'int64',
            
'int',
            
'date',
            
'container',
            
'boolean',
            
'anytype'
            
),
        
=> array( // Keywords
            
'window',
            
'while',
            
'try',
            
'true',
            
'throw',
            
'switch',
            
'super',
            
'static',
            
'server',
            
'right',
            
'return',
            
'retry',
            
'public',
            
'protected',
            
'private',
            
'print',
            
'pause',
            
'null',
            
'new',
            
'mod',
            
'left',
            
'interface',
            
'implements',
            
'if',
            
'for',
            
'final',
            
'false',
            
'extends',
            
'else',
            
'edit',
            
'do',
            
'div',
            
'display',
            
'default',
            
'continue',
            
'client',
            
'class',
            
'changeCompany',
            
'case',
            
'breakpoint',
            
'break',
            
'at',
            
'abstract'
            
),
        
=> array( // Functions within the Axapta kernel
            
'year',
            
'wkofyr',
            
'webwebpartstr',
            
'webstaticfilestr',
            
'websitetempstr',
            
'websitedefstr',
            
'webreportstr',
            
'webpagedefstr',
            
'weboutputcontentitemstr',
            
'webmenustr',
            
'webletitemstr',
            
'webformstr',
            
'webdisplaycontentitemstr',
            
'webactionitemstr',
            
'varstr',
            
'utilmoyr',
            
'uint2str',
            
'typeof',
            
'typeid',
            
'trunc',
            
'today',
            
'timenow',
            
'time2str',
            
'term',
            
'tanh',
            
'tan',
            
'tablestr',
            
'tablestaticmethodstr',
            
'tablepname',
            
'tablenum',
            
'tablename2id',
            
'tablemethodstr',
            
'tableid2pname',
            
'tableid2name',
            
'tablefieldgroupstr',
            
'tablecollectionstr',
            
'systemdateset',
            
'systemdateget',
            
'syd',
            
'substr',
            
'strupr',
            
'strscan',
            
'strrtrim',
            
'strrep',
            
'strrem',
            
'strprompt',
            
'strpoke',
            
'strnfind',
            
'strlwr',
            
'strltrim',
            
'strline',
            
'strlen',
            
'strkeep',
            
'strins',
            
'strfmt',
            
'strfind',
            
'strdel',
            
'strcolseq',
            
'strcmp',
            
'stralpha',
            
'str2time',
            
'str2num',
            
'str2int64',
            
'str2int',
            
'str2guid',
            
'str2enum',
            
'str2date',
            
'staticmethodstr',
            
'sln',
            
'sleep',
            
'sinh',
            
'sin',
            
'setprefix',
            
'sessionid',
            
'securitykeystr',
            
'securitykeynum',
            
'runbuf',
            
'runas',
            
'round',
            
'resourcestr',
            
'reportstr',
            
'refprintall',
            
'rate',
            
'querystr',
            
'pv',
            
'pt',
            
'prmisdefault',
            
'primoyr',
            
'prevyr',
            
'prevqtr',
            
'prevmth',
            
'power',
            
'pmt',
            
'num2str',
            
'num2date',
            
'num2char',
            
'nextyr',
            
'nextqtr',
            
'nextmth',
            
'newguid',
            
'mthofyr',
            
'mthname',
            
'mkdate',
            
'minint',
            
'min',
            
'methodstr',
            
'menustr',
            
'menuitemoutputstr',
            
'menuitemdisplaystr',
            
'menuitemactionstr',
            
'maxint',
            
'maxdate',
            
'max',
            
'match',
            
'logn',
            
'log10',
            
'literalstr',
            
'licensecodestr',
            
'licensecodenum',
            
'intvnorm',
            
'intvno',
            
'intvname',
            
'intvmax',
            
'int64str',
            
'int64str',
            
'indexstr',
            
'indexnum',
            
'indexname2id',
            
'indexid2name',
            
'idg',
            
'identifierstr',
            
'helpfilestr',
            
'helpdevstr',
            
'helpapplstr',
            
'guid2str',
            
'getprefix',
            
'getCurrentUTCTime',
            
'fv',
            
'funcname',
            
'frac',
            
'formstr',
            
'fieldstr',
            
'fieldpname',
            
'fieldnum',
            
'fieldname2id',
            
'fieldid2pname',
            
'fieldid2name',
            
'extendedTypeStr',
            
'extendedTypeNum',
            
'exp10',
            
'exp',
            
'evalbuf',
            
'enumstr',
            
'enumnum',
            
'enumcnt',
            
'enum2str',
            
'endmth',
            
'dimof',
            
'dg',
            
'decround',
            
'ddb',
            
'dayofyr',
            
'dayofwk',
            
'dayofmth',
            
'dayname',
            
'date2str',
            
'date2num',
            
'curuserid',
            
'curext',
            
'cterm',
            
'cosh',
            
'cos',
            
'corrflagset',
            
'corrflagget',
            
'convertUTCTimeToLocalTime',
            
'convertUTCDateToLocalDate',
            
'conpoke',
            
'conpeek',
            
'connull',
            
'conlen',
            
'conins',
            
'confind',
            
'configurationkeystr',
            
'configurationkeynum',
            
'condel',
            
'classstr',
            
'classnum',
            
'classidget',
            
'char2num',
            
'beep',
            
'atan',
            
'asin',
            
'ascii2ansi',
            
'any2str',
            
'any2real',
            
'any2int64',
            
'any2int',
            
'any2guid',
            
'any2enum',
            
'any2date',
            
'ansi2ascii',
            
'acos',
            
'abs'
            
),
        
=> array( // X++ SQL stuff
            
'where',
            
'update_recordset',
            
'ttsCommit',
            
'ttsBegin',
            
'ttsAbort',
            
'sum',
            
'setting',
            
'select',
            
'reverse',
            
'pessimisticLock',
            
'outer',
            
'order by',
            
'optimisticLock',
            
'notExists',
            
'noFetch',
            
'next',
            
'minof',
            
'maxof',
            
'like',
            
'join',
            
'insert_recordset',
            
'index hint',
            
'index',
            
'group by',
            
'from',
            
'forUpdate',
            
'forceSelectOrder',
            
'forcePlaceholders',
            
'forceNestedLoop',
            
'forceLiterals',
            
'flush',
            
'firstOnly',
            
'firstFast',
            
'exists',
            
'desc',
            
'delete_from',
            
'count',
            
'avg',
            
'asc'
            
)
        ),
    
'SYMBOLS' => array( // X++ symbols
        
'!',
        
'&',
        
'(',
        
')',
        
'*',
        
'^',
        
'|',
        
'~',
        
'+',
        
',',
        
'-',
        
'/',
        
':',
        
'<',
        
'=',
        
'>',
        
'?',
        
'[',
        
']',
        
'{',
        
'}'
        
),
    
'CASE_SENSITIVE' => array(
        
GESHI_COMMENTS => true,
        
=> false,
        
=> false,
        
=> false,
        
=> false
        
),
    
'STYLES' => array(
        
'KEYWORDS' => array(
            
=> 'color: #0000ff;',
            
=> 'color: #0000ff;',
            
=> 'color: #0000ff;',
            
=> 'color: #0000ff;'
            
),
        
'COMMENTS' => array(
            
=> 'color: #007f00;',
            
'MULTI' => 'color: #007f00; font-style: italic;'
            
),
        
'ESCAPE_CHAR' => array(
            
=> 'color: #000000;'
            
),
        
'BRACKETS' => array(
            
=> 'color: #000000;'
            
),
        
'STRINGS' => array(
            
=> 'color: #ff0000;'
            
),
        
'NUMBERS' => array(
            
=> 'color: #000000;'
            
),
        
'METHODS' => array(
            
=> 'color: #000000;',
            
=> 'color: #000000;'
            
),
        
'SYMBOLS' => array(
            
=> 'color: #00007f;'
            
),
        
'REGEXPS' => array(
            ),
        
'SCRIPT' => array(
            )
        ),
    
'URLS' => array(
        ),
    
'OOLANG' => true,
    
'OBJECT_SPLITTERS' => array(
        
=> '.',
        
=> '::'
        
),
    
'REGEXPS' => array(
        ),
    
'STRICT_MODE_APPLIES' => GESHI_NEVER,
    
'SCRIPT_DELIMITERS' => array(
        ),
    
'HIGHLIGHT_STRICT_BLOCK' => array(
        )
);

?>

:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ ok ]

:: Make Dir ::
 
[ ok ]
:: Make File ::
 
[ ok ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0156 ]--