!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/var/www/html/manage/class/   drwxr-xr-x
Free 52.6 GB of 127.8 GB (41.15%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     test.php (941 B)      -rw-r--r--
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
Information:
Path /var/www/html/manage/class/test.php
Size 941 B
MD5 4b790a981d3f4d43989d261653925184
Owner/Group apache/apache
Perms-rw-r--r--
Create time 03/07/2013 18:31:17
Access time 11/07/2024 18:10:41
MODIFY time 04/12/2007 09:35:10

FULL HEXDUMP
00000000
00000018
00000030
00000048
00000060
00000078
00000090
000000A8
000000C0
000000D8
000000F0
00000108
00000120
00000138
00000150
00000168
00000180
00000198
000001B0
000001C8
000001E0
000001F8
00000210
00000228
00000240
00000258
00000270
00000288
000002A0
000002B8
000002D0
000002E8
00000300
00000318
00000330
00000348
00000360
00000378
00000390
000003A8
3C 3F 0D 0A 69 6E 63 6C 75 64 65 28 22 63 6C 73 46 6F 72 6D 2E 70 68 70
22 29 3B 0D 0A 69 6E 63 6C 75 64 65 28 22 63 6C 73 54 61 62 6C 65 2E 70
68 70 22 29 3B 0D 0A 2F 2F 65 63 68 6F 20 24 73 65 78 5B 30 5D 2E 20 24
63 68 6B 31 5B 30 5D 3B 0D 0A 24 6F 46 20 3D 20 6E 65 77 20 63 6C 73 46
6F 72 6D 28 29 3B 0D 0A 24 6F 54 20 3D 20 6E 65 77 20 63 6C 73 54 61 62
6C 65 28 61 72 72 61 79 28 22 E1 B6 BA BB E9 D2 C2 22 2C 20 22 AA E8 CD
A7 20 69 6E 70 75 74 22 29 29 3B 0D 0A 24 6F 54 2D 3E 61 6C 69 67 6E 3D
22 63 65 6E 74 65 72 22 3B 0D 0A 24 68 74 6D 6C 20 3D 20 24 6F 46 2D 3E
53 74 61 72 74 28 22 66 31 22 29 3B 0D 0A 24 6F 54 2D 3E 61 64 64 52 6F
77 28 61 72 72 61 79 28 22 48 69 64 64 65 6E 22 2C 20 20 24 6F 46 2D 3E
48 69 64 64 65 6E 28 22 6D 65 74 68 6F 64 22 2C 20 22 61 64 64 22 29 29
29 3B 0D 0A 24 6F 54 2D 3E 61 64 64 52 6F 77 28 61 72 72 61 79 28 22 C3
CB D1 CA 22 2C 20 24 6F 46 2D 3E 54 65 78 74 28 22 70 73 49 64 22 2C 20
24 70 73 49 64 29 29 29 3B 0D 0A 24 6F 54 2D 3E 61 64 64 52 6F 77 28 61
72 72 61 79 28 22 54 65 78 74 41 72 65 61 22 2C 20 24 6F 46 2D 3E 54 65
78 74 61 72 65 61 28 22 64 65 73 63 22 2C 20 24 64 65 73 63 29 29 29 3B
0D 0A 24 6F 54 2D 3E 61 64 64 52 6F 77 28 61 72 72 61 79 28 22 52 61 64
69 6F 22 2C 20 24 6F 46 2D 3E 52 61 64 69 6F 28 22 73 65 78 5B 5D 22 2C
20 22 4D 22 2C 20 22 AA D2 C2 22 29 20 2E 20 24 6F 46 2D 3E 52 61 64 69
6F 28 22 73 65 78 5B 5D 22 2C 20 22 46 22 2C 22 CB AD D4 A7 22 29 29 29
3B 0D 0A 24 6F 54 2D 3E 61 64 64 52 6F 77 28 61 72 72 61 79 28 22 43 68
65 63 6B 42 6F 78 22 2C 20 24 6F 46 2D 3E 43 68 65 63 6B 62 6F 78 28 22
63 68 6B 31 5B 5D 22 2C 20 22 52 75 6E 22 2C 20 22 C7 D4 E8 A7 22 29 20
2E 20 24 6F 46 2D 3E 43 68 65 63 6B 62 6F 78 28 22 63 68 6B 31 5B 5D 22
2C 20 22 57 61 6C 6B 22 2C 20 22 E0 B4 D4 B9 22 29 29 29 3B 0D 0A 24 61
56 20 3D 20 61 72 72 61 79 28 31 2C 20 32 2C 20 33 2C 20 34 2C 20 35 29
3B 0D 0A 24 61 4C 20 3D 20 61 72 72 61 79 28 22 61 61 61 61 61 22 2C 22
62 62 62 62 62 22 2C 22 63 63 63 63 63 22 2C 22 64 64 64 64 64 22 2C 22
65 65 65 65 65 22 29 3B 0D 0A 24 6F 54 2D 3E 61 64 64 52 6F 77 28 61 72
72 61 79 28 22 53 65 6C 65 63 74 22 2C 20 24 6F 46 2D 3E 53 65 6C 65 63
74 28 22 6E 61 6D 65 22 2C 20 24 61 4C 2C 20 24 61 56 2C 20 24 6E 61 6D
65 29 29 29 3B 0D 0A 24 6F 54 2D 3E 61 64 64 72 6F 77 28 61 72 72 61 79
28 22 42 75 74 74 6F 6E 22 2C 20 24 6F 46 2D 3E 42 75 74 74 6F 6E 28 22
61 6C 65 72 74 28 27 48 6F 48 6F 48 6F 27 29 22 29 20 2E 20 24 6F 46 2D
3E 53 75 62 6D 69 74 28 29 20 2E 20 24 6F 46 2D 3E 52 65 73 65 74 28 29
29 29 3B 0D 0A 24 68 74 6D 6C 2E 3D 24 6F 54 2D 3E 6F 75 74 70 75 74 28
29 3B 0D 0A 24 68 74 6D 6C 2E 3D 20 24 6F 46 2D 3E 45 6E 64 28 29 3B 0D
0A 65 63 68 6F 20 24 68 74 6D 6C 3B 0D 0A 24 61 61 20 3D 20 22 31 32 33
34 78 78 78 78 78 78 78 78 78 78 78 78 78 78 78 78 78 78 78 78 78 78 22
3B 0D 0A 3F 3E
<?  include("clsForm.php
");  include("clsTable.p
hp");  //echo $sex[0]. $
chk1[0];  $oF = new clsF
orm();  $oT = new clsTab
le(array("ᶺ»éÒÂ", "ªèÍ
§ input"));  $oT->align=
"center";  $html = $oF->
Start("f1");  $oT->addRo
w(array("Hidden",  $oF->
Hidden("method", "add"))
);  $oT->addRow(array("Ã
ËÑÊ", $oF->Text("psId", 
$psId)));  $oT->addRow(a
rray("TextArea", $oF->Te
xtarea("desc", $desc)));
  $oT->addRow(array("Rad
io", $oF->Radio("sex[]",
 "M", "ªÒÂ") . $oF->Radi
o("sex[]", "F","Ë­Ô§")))
;  $oT->addRow(array("Ch
eckBox", $oF->Checkbox("
chk1[]", "Run", "ÇÔè§") 
. $oF->Checkbox("chk1[]"
, "Walk", "à´Ô¹")));  $a
V = array(1, 2, 3, 4, 5)
;  $aL = array("aaaaa","
bbbbb","ccccc","ddddd","
eeeee");  $oT->addRow(ar
ray("Select", $oF->Selec
t("name", $aL, $aV, $nam
e)));  $oT->addrow(array
("Button", $oF->Button("
alert('HoHoHo')") . $oF-
>Submit() . $oF->Reset()
));  $html.=$oT->output(
);  $html.= $oF->End(); 
 echo $html;  $aa = "123
4xxxxxxxxxxxxxxxxxxxxxx"
;  ?>

HEXDUMP: [Full] [Preview]
Base64:
[Encode [+chunk [+chunk+quotes [Decode


:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ ok ]

:: Make Dir ::
 
[ ok ]
:: Make File ::
 
[ ok ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0089 ]--