!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/var/www/html/alumni/templates/simple_grey/compiled/   drwxr-xr-x
Free 50.65 GB of 127.8 GB (39.63%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     home_def.php (7.27 KB)      -rw-r--r--
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
<?php $var['rain'] = $GLOBALS?>
<!-- home | generated by RainTPL v 1.0 | www.RainTPL.com -->
<!-- HEADER i -->
    <table width='100%' border='0' align='center' cellpadding='0' cellspacing='0'>
      <tr>
        <td></td>
        <td width='70%' valign='bottom'><table width='100%' border='0' align='center' cellpadding='0' cellspacing='0'><tr><td><a href='<?php echo $var["site_url"];?>' title='<?php echo $var["site_name"];?>'><img src='templates/<?php echo $var["tpl_template"];?>/images/logo.gif' border='0' alt='Logo'></a></td><td align='right' width='1'>
            <?php showBanner(1); ?>
        </td></tr></table></td>
        <td></td>
      </tr>
      <tr>
        <td colspan='3' class='tpl_minihead' height='12'></td>
      </tr>
      <tr>
        <td class='tpl_head_button_left' width='15%'></td>
        <td class='tpl_head_button' height='34'>
            <table width='100%' border='0' align='center' cellpadding='0' cellspacing='0'><tr><td align='left'><a href='index.php'><img src='templates/<?php echo $var["tpl_template"];?>/images/button_home.gif' width='80' height='34' border='0' alt='Home'></a><img src='templates/<?php echo $var["tpl_template"];?>/images/bg_bar_spacer.gif' width='2' height='34' alt='Spacer'><a href='index.php?page=download'><img src='templates/<?php echo $var["tpl_template"];?>/images/button_download.gif' width='80' height='34' border='0' alt='Download'></a><img src='templates/<?php echo $var["tpl_template"];?>/images/bg_bar_spacer.gif' width='2' height='34' alt='Spacer'><a href='index.php?page=forum'><img src='templates/<?php echo $var["tpl_template"];?>/images/button_forum.gif' width='80' height='34' border='0' alt='Forum'></a><img src='templates/<?php echo $var["tpl_template"];?>/images/bg_bar_spacer.gif' width='2' height='34' alt='Spacer'><a href='index.php?page=gallery'><img src='templates/<?php echo $var["tpl_template"];?>/images/button_gallery.gif' width='80' height='34' border='0' alt='Gallery'></a><img src='templates/<?php echo $var["tpl_template"];?>/images/bg_bar_spacer.gif' width='2' height='34' alt='Spacer'></a></td>
            </tr></table></td>
        <td class='tpl_head_button_right' width='15%'></td>
      </tr>
      <tr>
        <td class='tpl_head_red_left'></td>
        <td height='20' valign='top' class='tpl_head_red_center'>&nbsp;<?php echo $var["showpath"];?></td>
        <td class='tpl_head_red_right'></td>
      </tr>
<!-- HEADER e -->

      <tr>
        <td class='tpl_while_left'>&nbsp;</td>
        <td class='tpl_spacer_main'>
        
        <table width='100%' border='0' align='center' cellpadding='0' cellspacing='0'>
          <tr>
              <?php
    
if( $var["fullscreen"] < ){
?>
                  <td width='200' valign='top'>
                <div  class='tpl_blocks_nav'>
                    <!-- NAVIGATOR BLOCKS i -->
                    <?php
        
if( isset( $var["tpl_blocks_navigator"] ) ){
            
$counter1 0;
            foreach( 
$var["tpl_blocks_navigator"] as $key1 => $value1 ){ 
?>
                        <?php
            
if( $value1["usetitle"] > ){
?>
                            <div class='tpl_blocks_title'><?php echo $value1["title"];?></div>
                        <?php
            
}
?>
                        <div class='tpl_block'><?php echo $value1["content"];?></div>
                        <div class='tpl_vspacer'></div>
                    <?php
                $counter1
++;
            }
        }
?>
                    <!-- NAVIGATOR BLOCKS e -->
                </div>
                </td>
              <?php
    
}
?>
            <?php
    
if( $var["fullscreen"] < ){
?>
                <td valign='top' class='tpl_blocks_main'>
            <?php
    
}
        elseif( 
$var["fullscreen"] < ){
?>
                <td valign='top' colspan='2' class='tpl_blocks_main'>
            <?php
        
}
        else{
?>
                <td valign='top' colspan='3' class='tpl_blocks_main'>
            <?php
        
}
?>

            <!-- MAIN CONTENT i -->
                <!-- MESSAGES i -->
                <?php
        
if( isset( $var["tpl_messages"] ) ){
            
$counter1 0;
            foreach( 
$var["tpl_messages"] as $key1 => $value1 ){ 
?>                
                    <div class='tpl_messages_title'><img src='templates/<?php echo $var["tpl_template"];?>/images/arrow_slim.gif' alt='Arrow'>&nbsp;<?php echo $value1["title"];?></div>
                    <div><?php echo $value1["content"];?></div>
                    <div class='tpl_vspacer'></div>
                <?php
                $counter1
++;
            }
        }
?>
                <!-- MESSAGES e -->
                                    
                <!-- CENTRAL BLOCKS i -->
                <?php
        
if( isset( $var["tpl_blocks_central"] ) ){
            
$counter1 0;
            foreach( 
$var["tpl_blocks_central"] as $key1 => $value1 ){ 
?>
                    <?php
            
if( $value1["usetitle"] > ){
?>
                        <div class='tpl_blocks_title'><?php echo $value1["title"];?></div>
                    <?php
            
}
?>
                    <div class='tpl_block'><?php echo $value1["content"];?></div>
                    <div class='tpl_vspacer'></div>
                <?php
                $counter1
++;
            }
        }
?>
                <!-- CENTRAL BLOCKS e -->
                                    
                <!-- PAGE i -->
                <?php
        
if( $var["tpl_page"]["title"] != '' ){
?>
                    <div class='tpl_page_title'>
                    <?php
            
if( $var["tpl_page"]["url"] != '' ){
?>
                        <img src='templates/<?php echo $var["tpl_template"];?>/images/arrow.gif' alt='Arrow'>&nbsp;<a href='<?php echo $var["tpl_page"]["url"];?>' title='<?php echo $var["tpl_page"]["title"];?>'><b><?php echo $var["tpl_page"]["title"];?></b></a>
                        <div class='tpl_page_title_line'></div>
                    <?php
            
}
            else{
?>
                        <b><?php echo $var["tpl_page"]["title"];?></b>
                        <div class='tpl_page_title_line'></div>
                    <?php
            
}
?>
                    </div>
                    <div class='tpl_vspacer'></div>
                <?php
        
}
?>
                <?php
        
if( $var["tpl_page"]["name"] == 'blog' ){
?> <?php
$RainTPL_include_obj 
= new RainTPL();
$RainTPL_include_obj->assign$var );
$RainTPL_directory_template_temp $RainTPL_include_obj->tpl_dir;
$this->tpl_dir $GLOBALS'RainTPL_tpl_dir' ] = $RainTPL_include_obj->tpl_dir "/" dirname"blog" );
$RainTPL_include_obj->drawbasename"blog" ) );
$this->tpl_dir $GLOBALS'RainTPL_tpl_dir' ] = $RainTPL_directory_template_temp;
?> <?php
        
}
?>
                <?php
        
if( $var["tpl_page"]["name"] == 'news' ){
?> <?php
$RainTPL_include_obj 
= new RainTPL();
$RainTPL_include_obj->assign$var );
$RainTPL_directory_template_temp $RainTPL_include_obj->tpl_dir;
$this->tpl_dir $GLOBALS'RainTPL_tpl_dir' ] = $RainTPL_include_obj->tpl_dir "/" dirname"news" );
$RainTPL_include_obj->drawbasename"news" ) );
$this->tpl_dir $GLOBALS'RainTPL_tpl_dir' ] = $RainTPL_directory_template_temp;
?> <?php
        
}
?>
                <div><?php echo $var["tpl_page"]["content"];?></div>
                <!-- PAGE e -->
            <!-- MAIN CONTENT e -->
            
            </td>
                <?php
        
if( $var["fullscreen"] < ){
?>
                    <td width='160' valign='top'>
                        <div class='tpl_blocks_extra'>
                            <!-- EXTRA BLOCKS i -->
                            <?php
            
if( isset( $var["tpl_blocks_extra"] ) ){
                
$counter1 0;
                foreach( 
$var["tpl_blocks_extra"] as $key1 => $value1 ){ 
?>
                                <?php
                
if( $value1["usetitle"] > ){
?>
                                    <div class='tpl_blocks_title'><?php echo $value1["title"];?></div>
                                <?php
                
}
?>
                                <div class='tpl_block'><?php echo $value1["content"];?></div>
                                <div class='tpl_vspacer'></div>
                            <?php
                    $counter1
++;
                }
            }
?>
                            <!-- EXTRA BLOCKS e -->
                        </div>
                    </td>
                <?php
        
}
?>
              </tr>
            </table>
            </td>
            <td class='tpl_while_right'>&nbsp;</td>
          </tr>
          <tr>
            <td class='tpl_head_button_left'></td>
            <td class='tpl_head_button' height='15'><?php echo $var["copyright"];?></td>
            <td class='tpl_head_button_right'></td>
          </tr>
        </table>
        <div align="center"><?php echo $var["footmsg"];?></div>
        <div align="center"><?php echo $var["copytext"];?></div>
<!--/ home -->

:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ ok ]

:: Make Dir ::
 
[ ok ]
:: Make File ::
 
[ ok ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0131 ]--