!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/var/www/html/phpMyAdmin/libraries/   drwxr-xr-x
Free 52.35 GB of 127.8 GB (40.96%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     Theme.class.php (6.89 KB)      -rw-r--r--
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
loadInfo();
        $this->checkImgPath();
    }

    function loadInfo() {
        if ( ! file_exists( $this->getPath() . '/info.inc.php' ) ) {
            return false;
        }

        if ( $this->mtime_info === filemtime( $this->getPath() . '/info.inc.php' ) ) {
            return true;
        }

        @include( $this->getPath() . '/info.inc.php' );

        // did it set correctly?
        if ( ! isset( $theme_name ) ) {
            return false;
        }

        $this->mtime_info = filemtime( $this->getPath() . '/info.inc.php' );

        if ( isset( $theme_full_version ) ) {
            $this->setVersion( $theme_full_version );
        } elseif ( isset( $theme_generation, $theme_version ) ) {
            $this->setVersion( $theme_generation . '.' . $theme_version );
        }
        $this->setName( $theme_name );

        return true;
    }

    /**
     * returns theme object loaded from given folder
     * or false if theme is invalid
     *
     * @static
     * @param   string  path to theme
     * @return  object  PMA_Theme
     */
    function load( $folder ) {

        $theme = new PMA_Theme();

        $theme->setPath( $folder );

        if ( ! $theme->loadInfo() ) {
            return false;
        }

        $theme->checkImgPath();

        return $theme;
    }

    function checkImgPath() {
        if ( is_dir( $this->getPath() . '/img/' ) ) {
            $this->setImgPath( $this->getPath() . '/img/' );
            return true;
        } elseif ( is_dir( $GLOBALS['cfg']['ThemePath'] . '/original/img/' ) ) {
            $this->setImgPath( $GLOBALS['cfg']['ThemePath'] . '/original/img/' );
            return true;
        } else {
            $GLOBALS['PMA_errors'][] =
                sprintf( $GLOBALS['strThemeNoValidImgPath'], $this->getName() );
            trigger_error(
                sprintf( $GLOBALS['strThemeNoValidImgPath'], $this->getName() ),
                E_USER_WARNING );
            return false;
        }
    }

    /**
     * returns path to theme
     * @uses    $this->$path    as return value
     * @return  string  $path   path to theme
     */
    function getPath() {
        return $this->path;
    }

    /**
     * returns layout file
     *
     * @return  string  layout file
     */
    function getLayoutFile() {
        return $this->getPath() . '/layout.inc.php';
    }

    /**
     * set path to theme
     * @uses    $this->$path    to set it
     * @param   string  $path   path to theme
     */
    function setPath( $path ) {
        $this->path = trim( $path );
    }

    /**
     * sets version
     * @uses    $this->version
     * @param   string new version
     */
    function setVersion( $version ) {
        $this->version = trim( $version );
    }

    /**
     * returns version
     * @uses    $this->version
     * @return  string  version
     */
    function getVersion() {
        return $this->version;
    }

    /**
     * checks theme version agaisnt $version
     * returns true if theme version is equal or higher to $version
     *
     * @uses    version_compare()
     * @uses    $this->getVersion()
     * @param   string  $version    version to compare to
     * @return  boolean
     */
    function checkVersion( $version ) {
        return version_compare( $this->getVersion(), $version, 'lt' );
    }

    /**
     * sets name
     * @param   string  $name   new name
     */
    function setName( $name ) {
        $this->name = trim( $name );
    }

    /**
     * returns name
     * @return  string name
     */
    function getName() {
        return $this->name;
    }

    /**
     * sets id
     * @param   string  $id   new id
     */
    function setId( $id ) {
        $this->id = trim( $id );
    }

    /**
     * returns id
     * @return  string id
     */
    function getId() {
        return $this->id;
    }

    function setImgPath( $path ) {
        $this->img_path = $path;
    }

    function getImgPath() {
        return $this->img_path;
    }

    /**
     * load css (send to stdout, normaly the browser)
     *
     * @uses    $this->getPath()
     * @uses    $this->types
     * @uses    PMA_SQP_buildCssData()
     * @uses    file_exists()
     * @uses    in_array()
     * @param   string  $type   left, right or print
     */
    function loadCss( &$type ) {
        if ( empty( $type ) 
bool(false)

:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ ok ]

:: Make Dir ::
 
[ ok ]
:: Make File ::
 
[ ok ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0055 ]--