!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/var/www/html/stdalumni/system/libraries/Cache/drivers/   drwxr-xr-x
Free 49.64 GB of 127.8 GB (38.84%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     Cache_file.php (4.05 KB)      -rw-r--r--
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
<?php if ( ! defined('BASEPATH')) exit('No direct script access allowed');
/**
 * CodeIgniter
 *
 * An open source application development framework for PHP 4.3.2 or newer
 *
 * @package        CodeIgniter
 * @author        ExpressionEngine Dev Team
 * @copyright    Copyright (c) 2006 - 2011 EllisLab, Inc.
 * @license        http://codeigniter.com/user_guide/license.html
 * @link        http://codeigniter.com
 * @since        Version 2.0
 * @filesource    
 */

// ------------------------------------------------------------------------

/**
 * CodeIgniter Memcached Caching Class 
 *
 * @package        CodeIgniter
 * @subpackage    Libraries
 * @category    Core
 * @author        ExpressionEngine Dev Team
 * @link        
 */

class CI_Cache_file extends CI_Driver {

    protected 
$_cache_path;

    
/**
     * Constructor
     */
    
public function __construct()
    {
        
$CI =& get_instance();
        
$CI->load->helper('file');
        
        
$path $CI->config->item('cache_path');
    
        
$this->_cache_path = ($path == '') ? APPPATH.'cache/' $path;
    }

    
// ------------------------------------------------------------------------

    /**
     * Fetch from cache
     *
     * @param     mixed        unique key id
     * @return     mixed        data on success/false on failure
     */
    
public function get($id)
    {
        if ( ! 
file_exists($this->_cache_path.$id))
        {
            return 
FALSE;
        }
        
        
$data read_file($this->_cache_path.$id);
        
$data unserialize($data);
        
        if (
time() >  $data['time'] + $data['ttl'])
        {
            
unlink($this->_cache_path.$id);
            return 
FALSE;
        }
        
        return 
$data['data'];
    }

    
// ------------------------------------------------------------------------

    /**
     * Save into cache
     *
     * @param     string        unique key
     * @param     mixed        data to store
     * @param     int            length of time (in seconds) the cache is valid 
     *                        - Default is 60 seconds
     * @return     boolean        true on success/false on failure
     */
    
public function save($id$data$ttl 60)
    {        
        
$contents = array(
                
'time'        => time(),
                
'ttl'        => $ttl,            
                
'data'        => $data
            
);
        
        if (
write_file($this->_cache_path.$idserialize($contents)))
        {
            @
chmod($this->_cache_path.$id0777);
            return 
TRUE;            
        }

        return 
FALSE;
    }

    
// ------------------------------------------------------------------------

    /**
     * Delete from Cache
     *
     * @param     mixed        unique identifier of item in cache
     * @return     boolean        true on success/false on failure
     */
    
public function delete($id)
    {
        return 
unlink($this->_cache_path.$id);
    }

    
// ------------------------------------------------------------------------

    /**
     * Clean the Cache
     *
     * @return     boolean        false on failure/true on success
     */    
    
public function clean()
    {
        return 
delete_files($this->_cache_path);
    }

    
// ------------------------------------------------------------------------

    /**
     * Cache Info
     *
     * Not supported by file-based caching
     *
     * @param     string    user/filehits
     * @return     mixed     FALSE
     */
    
public function cache_info($type NULL)
    {
        return 
get_dir_file_info($this->_cache_path);
    }

    
// ------------------------------------------------------------------------

    /**
     * Get Cache Metadata
     *
     * @param     mixed        key to get cache metadata on
     * @return     mixed        FALSE on failure, array on success.
     */
    
public function get_metadata($id)
    {
        if ( ! 
file_exists($this->_cache_path.$id))
        {
            return 
FALSE;
        }
        
        
$data read_file($this->_cache_path.$id);        
        
$data unserialize($data);
        
        if (
is_array($data))
        {
            
$data $data['data'];
            
$mtime filemtime($this->_cache_path.$id);

            if ( ! isset(
$data['ttl']))
            {
                return 
FALSE;
            }

            return array(
                
'expire'     => $mtime $data['ttl'],
                
'mtime'        => $mtime
            
);
        }
        
        return 
FALSE;
    }

    
// ------------------------------------------------------------------------

    /**
     * Is supported
     *
     * In the file driver, check to see that the cache directory is indeed writable
     * 
     * @return boolean
     */
    
public function is_supported()
    {
        return 
is_really_writable($this->_cache_path);
    }

    
// ------------------------------------------------------------------------
}
// End Class

/* End of file Cache_file.php */
/* Location: ./system/libraries/Cache/drivers/Cache_file.php */

:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ Read-Only ]

:: Make Dir ::
 
[ Read-Only ]
:: Make File ::
 
[ Read-Only ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0083 ]--