!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/var/www/html/manage_22222/webboard/   drwxr-xr-x
Free 52.63 GB of 127.8 GB (41.18%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     webboard.php (11.54 KB)      -rw-r--r--
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
<?
include("config.inc.php");
if(
$online>=1){
include(
"useronline.php");
mysql_query("SET NAMES 'tis620'");
}
include(
"function.php");
if(empty(
$Category)){
            echo 
"<center><br>";
            echo 
"<font color=red size=+1> กรุณาระบุ Category ให้ตรงกับที่ web เปิดใช้ด้วยครับ</font>";
            echo 
"<br><br>";
            echo 
"<font color=red size=+1><b>[</b> <a href='javascript:history.back(1)'>กลับไปแก้ไข</a> <b>]</b></font>";
            echo 
"</center>";
        exit();        
    }
    else {
        
$Category CheckCategory($Category);  // ตรวจสอบว่าเป็น Category ที่อนุญาตหรือเปล่า
    
}
?>    

    <html>
    <head>
    <title><?echo $title?></title>
    <meta http-equiv="Content-Type" content="text/html; charset=tis-620">
    <link href="../source/style.css" rel="stylesheet" type="text/css">
    </head>
    
    <body bgcolor=#FFFFE0 background="pic/bg2.gif" onmouseover="window.status=' <?echo $title?> '; return true";
    onmouseout="window.status=' <?echo $title?> '; return true";>
<?
include("header.php");
?>
<center>
  <form method=post action="../webboard/search.php?Category=<? echo $Category?>" name="SearchForm" onSubmit="return check()">
    <table width=809 height="36" border=0 align="center">
      <tr>
        <td align=center width="35%" height="32">          <?
          
echo "สมาชิก 3 คนล่าสุด : ";
include(
"nuser.php");
echo 
"<br>";
echo 
" มี ";
include(
"alluser.php"); 
?>          <?
if($online>=1){
echo 
"มี " ."<font color=red>"." $users_online"."</font>" ." คน online ขณะนี้" ;}
?> <?
include("bd.php");
?></td>
        <td align=center  width="51%" height="32">         <div align="right">ค้นหาคำถาม
            <input type=text name="search" size=25 maxlength=100>
            <input type=submit value="Search">
        </div></td><td align=center  width="14%"><font size=2 face="MS Sans Serif"><a href="../webboard/postq.php?Category=<? echo $Category?>&page=<? echo $page?>"><img src="pic/post.gif" width="94" height="30" border="0"></a></font></td>
    </tr></table>
  </form>
  <hr align="center" width="809" color=1E90FF>
  <p><font size=2 face="MS Sans Serif"><a href="../webboard/postq.php?Category=<? echo $Category?>&page=<? echo $page?>">
    <?
// table อธิบายความหมายของรูปคำถาม
            ///echo"<table width=809 height="36" border=0 align=center">;
        
echo "<table width=809 height=36 border=0 bordercolor=black cellspacing=0 cellpadding=2>\n";
        echo 
"<tr><td align=left>\n";
        
//echo "\t &nbsp;<img src='../webboard/pic/cam.gif' border=\"0\"> - คำถามที่มีรูป \n";
        
echo "\t&nbsp;<img src='../webboard/pic/new2day.gif' border=\"0\"> - คำถามที่มีคนตั้งใหม่วันนี้ \n";
        echo 
"\t &nbsp;<img src='../webboard/pic/update2day.gif' border=\"0\"> - คำถามที่มีคนตอบวันนี้\n";
        
        echo 
"</td></tr>\n";
        echo 
"</table>\n\n";
        echo  
"<br>";

    include(
"config.inc.php");
    
$chk_date substr(date("Y-m-d H:i:s"),-19,-9);
    
    if (empty(
$page)){
        
$page=1;
    }

    
// ติดต่อ database เพื่ออ่านข้อมูล    
    // หาจำนวนหน้าทั้งหมด
    
mysql_connect($host,$user,$passwd);
    
mysql_query("SET NAMES 'tis620'");
    
$sql "select No from webboard_data where Category='$Category'";
    
$result mysql_db_query($dbname,$sql);
    
$NRow mysql_num_rows($result);
    
$rt $NRow%$list_page;
    if(
$rt!=0) { 
        
$totalpage floor($NRow/$list_page)+1
    }
    else {
        
$totalpage floor($NRow/$list_page); 
    }
    
$goto = ($page-1)*$list_page;



    
// Query ข้อมูลตามจำนวนที่กำหนด
    
$sql "select * from webboard_data where Category='$Category' order by No DESC limit $goto,$list_page";
    
$result mysql_db_query($dbname,$sql);
    
$NRow mysql_num_rows($result);

    if(
$NRow==0) { 
        echo 
"<center>";
        echo 
"<br>";
        echo 
"<font size=2 face='MS Sans Serif'>ยังไม่มีคำถาม เมื่อไหร่จะมีน้อ</font><br><br>\n";
        echo 
"<center>";
    }
    
// แสดงหัวข้อของบอร์ด
    
else {
        echo 
"<table  width=809 height=36 border=1 bordercolor=black cellspacing=0 cellpadding=2>\n";
        echo 
"<tr bgcolor= dodgerblue>\n";
        echo 
"\t<td align=center width=8%><font size=2 color=#FFF8DC><b>คำถามที่</b></font></td>\n";
        echo 
"\t<td align=center width=47% ><font size=2 color=#FFF8DC><b>คำถาม-[จำนวนคำตอบ] [จำนวนคนเข้าอ่าน]</b></font></td>\n";
        echo 
"\t<td align=center width=24%><font size=2 color=#FFF8DC><b>ผู้ถาม[วันที่ถาม]</b></font></td>\n";
        echo 
"\t<td align=center width=18%><font size=2 color=#FFF8DC><b>ผู้ตอบ[วันที่ตอบ]</b></font></td>\n";
        echo 
"</tr>\n\n";

        
// วนลูปแสดงข้อมูลที่อ่านได้
        
while ($row mysql_fetch_array($result)) {
            
            
// กำหนดสีของตาราง เพื่อให้มีการสลับสี
            //$bgc = ($bgc=="lightcyan") ? "powderblue" : "lightcyan";

            
$bgc = ($bgc==$rowColor1) ? $rowColor2 $rowColor1

            
// กำหนดค่าตัวแปร
            
$No sprintf("%05d",$row["No"]);
            
$Question $row["Question"];
            
$Name $row["Name"];
            
$Namer $row["Namer"];
            
$Member $row["Member"];
            
$Memberr $row["Memberr"];
            
$nphoto $row["nphoto"];
            
$ckDate trim(substr($row["Date"],-19,-9)); // แสดงเฉพาะวันที่
            
$Date convert_date($row["Date"]);
            
$Reply $row["Reply"];

            
$ckReplyDate trim(substr($row["ReplyDate"],-19,-9)); 
            
$ReplyDate convert_date($row["ReplyDate"]);
            
$pageviewdata $row["pageview"];
            
// แสดงเฉพาะวันที่
            
if($Date==$chk_date) {
                echo 
"<tr bgcolor=$rowHiLight>\n";
                    
                }elseif(
$ReplyDate==$chk_date) {

                echo 
"<tr bgcolor=$rowHiLight>\n";    
        }else {
            echo 
"<tr bgcolor=$bgc>\n";            
                }
            
// แสดงรูป folder
            
                    ////new
                 
               
if($Reply>="10" )
                    
                {
                echo 
"\t<td align=center><img src='../webboard/pic/hotfd.gif'> $No</td>\n";
               }
             elseif(
$ReplyDate!=""
                     
                       {
                    echo 
"\t<td align=center><img src='../webboard/pic/openfd.gif'> $No</td>\n";
                      } 
             elseif(
$Date==$chk_date
                {
                echo 
"\t<td  align=center ><img src='../webboard/pic/newfd.gif'> $No</td>\n";
                      } 
                      
                     else {
                    echo 
"\t<td align=center><img src='../webboard/pic/closefd.gif'> $No</td>\n";
                           }


            if((
$ckReplyDate==$chk_date)&&($nphoto!='')&&($ckDate==$chk_date))            {
            echo 
"\t<td><a href='show.php?Category=$Category&No=$row[No]' target='$No'>$Question</a> <img src='../webboard/pic/cam.gif' border=\"0\"><img src='../webboard/pic/new2day.gif' border=\"0\"> <img src='../webboard/pic/update2day.gif' border=\"0\"></font>&nbsp;[<font color=red> $Reply </font>] [<font color=red> $pageviewdata </font>]</td>\n";
            }
            elseif((
$ckReplyDate==$chk_date)&&($nphoto!=''))            {
            echo 
"\t<td><a href='show.php?Category=$Category&No=$row[No]' target='$No'>$Question</a> <img src='../webboard/pic/cam.gif' border=\"0\"><font color=red size='2'> <img src='../webboard/pic/update2day.gif' border=\"0\"></font>&nbsp;[<font color=red> $Reply </font>] [<font color=red> $pageviewdata </font>]</td>\n";
            }
            elseif((
$ckReplyDate==$chk_date) &&($ckDate==$chk_date))
                {echo 
"\t<td ><a href='show.php?Category=$Category&No=$row[No]' target='$No'>$Question</a> <font color=red size='2'> <img src='../webboard/pic/new2day.gif' border=\"0\"> <img src='../webboard/pic/update2day.gif' border=\"0\"></font>&nbsp;[<font color=red> $Reply </font>] [<font color=red> $pageviewdata </font>]</td>\n";
                      } 
            elseif(
$ckReplyDate==$chk_date)
                {echo 
"\t<td  ><a href='show.php?Category=$Category&No=$row[No]' target='$No'>$Question</a> <font color=red size='2'> <img src='../webboard/pic/update2day.gif' border=\"0\"></font>&nbsp;[<font color=red> $Reply </font>]   [<font color=red> $pageviewdata </font>]</td>\n";
                      } 
                      elseif((
$nphoto!='') &&($ckDate==$chk_date))
                {echo 
"\t<td ><a href='show.php?Category=$Category&No=$row[No]' target='$No'>$Question </a><img src='../webboard/pic/new2day.gif' border=\"0\"> <img src='../webboard/pic/cam.gif' border=\"0\">&nbsp;[<font color=red> $Reply </font>] [<font color=red> $pageviewdata </font>]</td>\n";
                
                      } 
                    
                      elseif(
$nphoto!=''
                {echo 
"\t<td ><a href='show.php?Category=$Category&No=$row[No]' target='$No'>$Question </a> <img src='../webboard/pic/cam.gif' border=\"0\">&nbsp;[<font color=red> $Reply </font>] [<font color=red> $pageviewdata </font>]</td>\n";
                
                      } 
                    
                       elseif(
$ckDate==$chk_date
                {echo 
"\t<td ><a href='show.php?Category=$Category&No=$row[No]' target='$No'>$Question </a> <img src='../webboard/pic/new2day.gif' border=\"0\">&nbsp;[<font color=red> $Reply </font>] [<font color=red> $pageviewdata </font>]</td>\n";
                
                      } 
            

            else{
                echo 
"\t<td><a href='show.php?Category=$Category&No=$row[No]' target='$No'>$Question</a>&nbsp;[<font color=red> $Reply </font>] [<font color=red> $pageviewdata </font>]</td>\n";
                     }            

            if(
$Member) {
                echo 
"\t<td>$Name <img src='../webboard/pic/online.gif'> <font color=blue> [$Date]</font></td>\n";
            }
            else {
                echo 
"\t<td>$Name <font color=blue> [$Date]</font></td>\n";
            }
            
            
// ตรวจสอบว่ามีคนตอบคำถามหรือยัง
if($Memberr) {
            if(
$ckReplyDate!="" 
                {
                echo 
"\t<td>$Namer <img src='../webboard/pic/online.gif'> <font color=blue>[$ReplyDate]</font></td>\n";
                }
            else 
                {
                echo 
"\t<td> ยังไม่มีคนตอบ </td>\n";
                }
            echo 
"</tr>\n\n";
            
        }else{
        if(
$ckReplyDate!="" 
                {
                echo 
"\t<td> $Namer <font color=blue>[$ReplyDate]</font></td>\n";
                }
            else 
                {
                echo 
"\t<td> ยังไม่มีคนตอบ </td>\n";
                }
            echo 
"</tr>\n\n";
        }
        
        }
        
        echo 
"</table>\n\n";
        
        
        
        
// table อธิบายความหมายของรูป
        
        
echo "<table  width=809 height=36 border=0 bordercolor=black cellspacing=0 cellpadding=2>\n";
        echo 
"<tr><td align=left>\n";
        echo 
"\t<img src='../webboard/pic/newfd.gif'> - คำถามใหม่ \n";
        echo 
"\t<img src='../webboard/pic/closefd.gif'> - คำถามเก่า \n";
        echo 
"\t<img src='../webboard/pic/openfd.gif'> - คำถามที่ถูกตอบแล้ว\n";
        echo 
"\t<img src='../webboard/pic/hotfd.gif'> - คำถามที่มีคนตอบมาก\n";
        echo 
"\t<img src='../webboard/pic/cam.gif'> - คำถามที่มีรูป\n";
        echo 
"\t<img src='../webboard/pic/online.gif'> - สมาชิกเว็บบอร์ด\n";
        echo 
"</td></tr>\n";
        echo 
"</table>\n\n";

        
// table แสดงเลขหน้า
        
echo "<table  width=809 height=36 border=0 bordercolor=black cellspacing=0 cellpadding=2>\n";
        echo 
"<tr><td align=left>\n";
        echo 
"\t<font size=2 color=#9400D3>\n";

        
// สร้าง link เพื่อไปหน้าก่อน-หน้าถัดไป
        
if($page>&& $page<=$totalpage) {
            
$prevpage $page-1;
            echo 
"\t<a href='../webboard/webboard.php?Category=$Category&page=$prevpage'>[หน้าก่อน = $prevpage]</a>\n";
        }

        echo 
"\t กำลังแสดงหน้าที่ $page/$totalpage \n";

        if(
$page!=$totalpage) {
            
$nextpage $page+1;
            echo 
"\t<a href='../webboard/webboard.php?Category=$Category&page=$nextpage'>[หน้าถัดไป = $nextpage]</a>\n";
        }

        echo 
"\t</font>\n";
        echo 
"</td></tr>\n";
        echo 
"<tr><td>\n";

        
// วนลูปแสดงเลขหน้าทั้งหมด
        
for($i=$i<$page $i++) {
            echo 
"\t<a href='../webboard/webboard.php?Category=$Category&page=$i'>$i</a> \n";
        }
        echo 
"\t<font size=2 color=red><b>$page</b></font> \n";
        for(
$i=$page+$i<=$totalpage $i++) {
            echo 
"\t<a href='../webboard/webboard.php?Category=$Category&page=$i'>$i</a> \n";
        }
    
        echo 
"</td></tr>\n";
        echo 
"</table>\n";
    }
?>
  <img src="pic/post.gif" width="94" height="30" border="0"></a></font>  </p>
  <hr width="809" color=1E90FF>
  <font size=1 face="MS Sans Serif"> </font> 
</center>

<script language="JavaScript">
<!--
function check()
{
      var v1 = document.SearchForm.search.value;
        if ( v1.length==0)
           {
           alert("กรุณาป้อนคำที่ต้องการค้นหา");
           document.SearchForm.search.focus();
           return false;
           }
         else
           return true;
}
//-->
</script>
</body>
</html>

:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ Read-Only ]

:: Make Dir ::
 
[ Read-Only ]
:: Make File ::
 
[ Read-Only ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0085 ]--