!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/var/www/html/alumni/templates/myblog/compiled/   drwxr-xr-x
Free 50.92 GB of 127.8 GB (39.84%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     home_def.php (11.96 KB)      -rw-r--r--
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |

<?php $var['rain'] = $GLOBALS?>
<!-- home | generated by RainTPL v 1.0 | www.RainTPL.com -->
<!-- HEADER i -->
<div class="tpl_top_bar">&nbsp;<?php echo $var["showpath"];?></div>
<div class="tpl_head">
    <table width="900" border="0" cellpadding="0" cellspacing="0" align="center">
        <tr>
            <td class="tpl_logo"><a href='<?php echo $var["site_url"];?>' title='<?php echo $var["site_name"];?>'><?php echo $var["site_name"];?></a></td>
            <td valign="bottom" align="right"><a href="index.php?page=rss" title="RSS"><img src="templates/myblog/images/tpl_rss_0.gif" border="0" alt='RSS'></a></td>
        </tr>
        <tr>
            <td width="550"><div class="tpl_search_bg"><div class="tpl_search_str">
            <form name='cerca' id='cerca' action='index.php?page=search' method='post'>
                <input name='query' type='text' id='query' size='33' value='<?php echo _SEARCH_."..."?>' maxlength='100' class='tpl_search_txt' onfocus="this.value=''">
                <input type='hidden' name='results' value='10'>
                <input type='hidden' name='where' value='all'>
            </form>
            </div></div></td>
            <td width="350" align="right"><a href="index.php?page=rss" title="RSS"><img src="templates/myblog/images/tpl_rss_1.gif" border="0" alt='RSS'></a></td>
        </tr>
    </table>
</div>
<!-- HEADER e -->

<table width="100%" border="0" cellpadding="0" cellspacing="0" align="center"><tr>
    <td class="tpl_main_left">&nbsp;</td>
    <td width="900">
        <table width="100%" border="0" cellpadding="0" cellspacing="0" align="center"><tr>
            <?php
    
if( $var["fullscreen"] < ){
?>
                <td width='550' class='tpl_main_left' valign='top' style='padding:8px 8px 0 0;'>
            <?php
    
}
        elseif( 
$var["fullscreen"] < ){
?>
                <td width='738' class='tpl_main_left' valign='top' style='padding:8px 8px 0 0;'>
            <?php
        
}
        else{
?>
                <td width='900' class='tpl_main_left' valign='top' style='padding-top:8px;'>
            <?php
        
}
?>

            <!-- MAIN CONTENT i -->
                <!-- MESSAGES i -->
                <?php
        
if( isset( $var["tpl_messages"] ) ){
            
$counter1 0;
            foreach( 
$var["tpl_messages"] as $key1 => $value1 ){ 
?>
                    <div class='tpl_mex_box'><?php echo $value1["content"];?></div>
                    <div class='tpl_vspacer'></div>
                <?php
                $counter1
++;
            }
        }
?>
                <!-- MESSAGES e -->
                                    
                <!-- CENTRAL BLOCKS i -->
                <?php
        
if( isset( $var["tpl_blocks_central"] ) ){
            
$counter1 0;
            foreach( 
$var["tpl_blocks_central"] as $key1 => $value1 ){ 
?>
                    <?php
            
if( $value1["usetitle"] > ){
?>
                        <div class='tpl_block_title_c'><h2><?php echo $value1["title"];?></h2></div>
                    <?php
            
}
?>
                    <div class='tpl_block_body_c'><?php echo $value1["content"];?></div>
                    <div class='tpl_vspacer'></div>
                <?php
                $counter1
++;
            }
        }
?>
                <!-- CENTRAL BLOCKS e -->
                                    
                <!-- PAGE i -->
                <?php
        
if( $var["tpl_page"]["title"] != '' ){
?>
                    <div class='tpl_page_title'>
                    <?php
            
if( $var["tpl_page"]["url"] != '' ){
?>
                        <a href='<?php echo $var["tpl_page"]["url"];?>' title='<?php echo $var["tpl_page"]["title"];?>'><b><h1><?php echo $var["tpl_page"]["title"];?></h1></b></a>
                    <?php
            
}
            else{
?>
                        <b><h1><?php echo $var["tpl_page"]["title"];?></h1></b>
                    <?php
            
}
?>
                    </div>
                    <div class='tpl_vspacer'></div>
                <?php
        
}
?>
                <?php
        
if( $var["tpl_page"]["name"] == 'blog' ){
?> <?php
$RainTPL_include_obj 
= new RainTPL();
$RainTPL_include_obj->assign$var );
$RainTPL_directory_template_temp $RainTPL_include_obj->tpl_dir;
$this->tpl_dir $GLOBALS'RainTPL_tpl_dir' ] = $RainTPL_include_obj->tpl_dir "/" dirname"blog" );
$RainTPL_include_obj->drawbasename"blog" ) );
$this->tpl_dir $GLOBALS'RainTPL_tpl_dir' ] = $RainTPL_directory_template_temp;
?> <?php
        
}
?>
                <?php
        
if( $var["tpl_page"]["name"] == 'news' ){
?> <?php
$RainTPL_include_obj 
= new RainTPL();
$RainTPL_include_obj->assign$var );
$RainTPL_directory_template_temp $RainTPL_include_obj->tpl_dir;
$this->tpl_dir $GLOBALS'RainTPL_tpl_dir' ] = $RainTPL_include_obj->tpl_dir "/" dirname"news" );
$RainTPL_include_obj->drawbasename"news" ) );
$this->tpl_dir $GLOBALS'RainTPL_tpl_dir' ] = $RainTPL_directory_template_temp;
?> <?php
        
}
?>
                <div><?php echo $var["tpl_page"]["content"];?></div>
                <!-- PAGE e -->
            <!-- MAIN CONTENT e -->
            
            </td>
            <?php
        
if( $var["fullscreen"] < ){
?>
                <td width='350' class='tpl_main_right' style='border-left:1px solid #FFF;' valign='top'>
                    <table width='100%' border='0' cellpadding='0' cellspacing='0'><tr>
                        <td width='180' style='padding:8px 8px 0 8px;' valign='top'>
                            <!-- EXTRA BLOCKS i -->
                            <?php
            
if( isset( $var["tpl_blocks_extra"] ) ){
                
$counter1 0;
                foreach( 
$var["tpl_blocks_extra"] as $key1 => $value1 ){ 
?>
                                <?php
                
if( $value1["usetitle"] > ){
?>
                                    <div class='tpl_block_title_e'><h2><?php echo $value1["title"];?></h2></div>
                                <?php
                
}
?>
                                <div class='tpl_block_body_e'><?php echo $value1["content"];?></div>
                                <div class='tpl_vspacer'></div>
                            <?php
                    $counter1
++;
                }
            }
?>
                            <!-- EXTRA BLOCKS e -->
                        </td>
                        <td width='146' style='padding:8px 0 0 8px; border-left:1px solid #FFF;' valign='top'>
                            <!-- NAVIGATOR BLOCKS i -->
                            <?php
            
if( isset( $var["tpl_blocks_navigator"] ) ){
                
$counter1 0;
                foreach( 
$var["tpl_blocks_navigator"] as $key1 => $value1 ){ 
?>
                                <?php
                
if( $value1["usetitle"] > ){
?>
                                    <div class='tpl_block_title'><h2><?php echo $value1["title"];?></h2></div>
                                <?php
                
}
?>
                                <div class='tpl_block_body'><?php echo $value1["content"];?></div>
                                <div class='tpl_vspacer'></div>
                            <?php
                    $counter1
++;
                }
            }
?>
                            <!-- NAVIGATOR BLOCKS e -->
                        </td>
                    </tr></table>
                </td>
            <?php
        
}
            elseif( 
$var["fullscreen"] < ){
?>
                <td width='160' class='tpl_main_right' valign='top'>
                    <table width='100%' border='0' cellpadding='0' cellspacing='0'><tr>
                        <td width='146' style='padding:8px 0 0 8px; border-left:1px solid #FFF;' valign='top'>
                            <!-- NAVIGATOR BLOCKS i -->
                            <?php
                
if( isset( $var["tpl_blocks_navigator"] ) ){
                    
$counter1 0;
                    foreach( 
$var["tpl_blocks_navigator"] as $key1 => $value1 ){ 
?>
                                <?php
                    
if( $value1["usetitle"] > ){
?>
                                    <div class='tpl_block_title'><h2><?php echo $value1["title"];?></h2></div>
                                <?php
                    
}
?>
                                <div class='tpl_block_body'><?php echo $value1["content"];?></div>
                                <div class='tpl_vspacer'></div>
                            <?php
                        $counter1
++;
                    }
                }
?>
                            <!-- NAVIGATOR BLOCKS e -->
                        </td>
                    </tr></table>
                </td>
            <?php
            
}
?>
            </tr></table>
        </td>
    <td class="tpl_main_right">&nbsp;</td>
    </tr></table>
    
    <?php
    
if (!defined("_RECENT_POSTS_")) { define("_RECENT_POSTS_","Recent posts"); }
    if (!
defined("_RECENT_COMMENTS_")) { define("_RECENT_COMMENTS_","Recent comments"); }
    global 
$dblink,$siteConfig;
    
?>
    
    <div class="tpl_foot" align="center">
        <div id="sub" align="left">
            
            <table width="900" border="0" cellpadding="0" cellspacing="0">
            <tr>
                <td width="33%" valign="top">
                    <div style='margin-bottom:4px;' class='tpl_foot_title'><?php echo _RECENT_POSTS_?></div>
                    <?php
                    $result 
$dblink->get_list("SELECT title FROM memht_blog_posts WHERE enabled=1 ORDER BY id DESC LIMIT 5");
                    foreach (
$result as $row) {
                        
$title outCode($row['title']);
                        
                        echo 
"<div style='padding:2px 0;'><img src='templates/".$siteConfig['template']."/images/page_white.gif' border='0' alt='Bullet'> <span style='vertical-align: top;'><a href='index.php?page=blog&title=".urlencode($title)."' title=\"$title\">$title</a></span></div>\n";
                    }
                    
?>
                </td>
                <td width="33%" valign="top">
                    <div style='margin-bottom:4px;' class='tpl_foot_title'><?php echo _RECENT_COMMENTS_?></div>
                    <?php
                    $result 
$dblink->get_list("SELECT name,text FROM memht_comments WHERE moderate=0 ORDER BY id DESC LIMIT 5");
                    foreach (
$result as $row) {
                        
$name outCode($row['name']);
                        
$text outCode($row['text']);
                        
                        echo 
"<div style='padding:2px 0;'><img src='templates/".$siteConfig['template']."/images/page_white.gif' border='0' alt='Bullet'> <span style='vertical-align: top;'>$name: <i>".trimString($text,25,1)."</i></a></span></div>\n";
                    }
                    
?>
                </td>
                <td width="33%" valign="top">
                    <div style='margin-bottom:4px;' class='tpl_foot_title'><?php echo _RSS_FEEDS_?></div>
                    <?php
                    
if ($dblink->get_num("SELECT id FROM memht_articoli WHERE enabled=1")>0) {
                        
$link = ($siteConfig['modrewrite']) ? "rss-articles.xml" "rss.php?page=articles";
                        echo 
"<div style='padding:2px 0;'><a href='$link' title='"._ARTRSSFEED_."' target='_blank'><img src='images/rss-syndicate_box.gif' style='vertical-align:baseline' title='"._ARTRSSFEED_."' border='0' alt='RSS'> <span style='vertical-align: top;'>"._ARTRSSFEED_."</span></a></div>\n";
                    }
                    if (
$dblink->get_num("SELECT id FROM memht_blog_posts WHERE enabled=1 LIMIT 1 ")>0) {
                        
$link = ($siteConfig['modrewrite']) ? "rss-blog.xml" "rss.php?page=blog";
                        echo 
"<div style='padding:2px 0;'><a href='$link' title='"._BLOGRSSFEED_."' target='_blank'><img src='images/rss-syndicate_box.gif' style='vertical-align:baseline' title='"._BLOGRSSFEED_."' border='0' alt='RSS'> <span style='vertical-align: top;'>"._BLOGRSSFEED_."</span></a></div>\n";
                    }
                    if (
$dblink->get_num("SELECT id FROM memht_download")>0) {
                        
$link = ($siteConfig['modrewrite']) ? "rss-download.xml" "rss.php?page=download";
                        echo 
"<div style='padding:2px 0;'><a href='$link' title='"._DWNRSSFEED_."' target='_blank'><img src='images/rss-syndicate_box.gif' style='vertical-align:baseline' title='"._DWNRSSFEED_."' border='0' alt='RSS'> <span style='vertical-align: top;'>"._DWNRSSFEED_."</span></a></div>\n";
                    }            
                    if (
$dblink->get_num("SELECT id FROM memht_forum_posts")>0) {
                        
$link = ($siteConfig['modrewrite']) ? "rss-forum.xml" "rss.php?page=forum";
                        echo 
"<div style='padding:2px 0;'><a href='$link' title='"._FORUMRSSFEED_."' target='_blank'><img src='images/rss-syndicate_box.gif' style='vertical-align:baseline' title='"._FORUMRSSFEED_."' border='0' alt='RSS'> <span style='vertical-align: top;'>"._FORUMRSSFEED_."</span></a></div>\n";
                    }
                    if (
$dblink->get_num("SELECT id FROM memht_guide WHERE enabled=1")>0) {
                        
$link = ($siteConfig['modrewrite']) ? "rss-guide.xml" "rss.php?page=guide";
                        echo 
"<div style='padding:2px 0;'><a href='$link' title='"._GUIRSSFEED_."' target='_blank'><img src='images/rss-syndicate_box.gif' style='vertical-align:baseline' title='"._GUIRSSFEED_."' border='0' alt='RSS'> <span style='vertical-align: top;'>"._GUIRSSFEED_."</span></a></div>\n";
                    }
                    if (
$dblink->get_num("SELECT id FROM memht_news WHERE enabled=1")>0) {
                        
$link = ($siteConfig['modrewrite']) ? "rss-news.xml" "rss.php?page=news";
                        echo 
"<div style='padding:2px 0;'><a href='$link' title='"._NEWSRSSFEED_."' target='_blank'><img src='images/rss-syndicate_box.gif' style='vertical-align:baseline' title='"._NEWSRSSFEED_."' border='0' alt='RSS'> <span style='vertical-align: top;'>"._NEWSRSSFEED_."</span></a></div>\n";
                    }
                    
$link = ($siteConfig['modrewrite']) ? "sitemap.xml" "sitemap.php";
                    echo 
"<div style='padding:2px 0;'><a href='$link' target='_blank' title='Sitemap'><img src='images/rss-syndicate_box.gif' style='vertical-align:baseline' title='Sitemap' border='0' alt='Sitemap'> <span style='vertical-align: top;'>Sitemap</span></a></div>\n";
                    
?>
                </td>
            </tr>
            </table>

            <div class='tpl_foot_text' style='margin-top:10px;'>
                <div><?php echo $var["copyright"];?></div>
                <div><?php echo $var["footmsg"];?></div>
                <div><?php echo $var["copytext"];?></div>
                <div>Template designed by <a href='http://www.memht.com' title='MemHT.com'>MemHT.com</a></div>
            </div>
        </div>
    </div>
<!--/ home -->

:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ ok ]

:: Make Dir ::
 
[ ok ]
:: Make File ::
 
[ ok ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0148 ]--