!C99Shell v. 1.0 pre-release build #16!

Software: Apache/2.0.54 (Fedora). PHP/5.0.4 

uname -a: Linux mina-info.me 2.6.17-1.2142_FC4smp #1 SMP Tue Jul 11 22:57:02 EDT 2006 i686 

uid=48(apache) gid=48(apache) groups=48(apache)
context=system_u:system_r:httpd_sys_script_t
 

Safe-mode: OFF (not secure)

/home/mnnews/public_html/mina/minabusiness/admin/   drwxr-xr-x
Free 3.89 GB of 27.03 GB (14.4%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     checkPasswd.inc.php3 (1.77 KB)      -rwxr-xr-x
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
<?
  
require("$mysqlCall");

  
$pass = crypt($pass, $user);
  
  
$query = "SELECT * FROM $users where  user=\"$user\" and  pass=\"$pass\"";
  
  
$mysql_result = mysql_query($query, $mysql_link);
  
  
  if(
$row = mysql_fetch_row($mysql_result))
    {
      
$fetch_ID =        $row[0];
      
$fetch_user =         $row[1];
      
$fetch_pass =         $row[2];
      
$fetch_superuser =     $row[3];
      
$fetch_email =        $row[4];
      
$active =                 $row[6];

      if(
$active)
    {
    
      if(
$fetch_superuser == 1)
        {
      
          
$remote_addr = $REMOTE_ADDR;
         
          
$superSession = SessionID(30);
          
          
//insert session to database
          
$Query = "INSERT INTO $superSessionT ";
          
$Query .= "VALUES ('$superSession', now(), '$fetch_ID', '$remote_addr') ";
          
mysql_query($Query, $mysql_link);

          
printSuperGUI($mode, $user, $fetch_email, $superSession, $fetch_ID, $config);
          
$realuser  = 1;
              
        }
      else
        {          
          
$remote_addr = $REMOTE_ADDR;
         
          
$session = SessionID(30);
          
          
//insert session to database
          
$Query = "INSERT INTO $normalSessionT ";
          
$Query .= "VALUES ('$session', now(), '$fetch_ID', '$remote_addr') ";
          
mysql_query($Query, $mysql_link);
          
          
          
printNormalGUI($mode, $user, $fetch_email, $session, $fetch_ID, $config);
          
$realuser = 1;
        
        }    
      
    }
      else
    {
      print(
"Your account has been de-activated<br>");
      
$realuser = 1;
    }

      
    }
  



  if(!isset(
$realuser))
    {
      
      print(
"<br>You are not registered or the password provided is incorect<br>Please try again or go way :)<br>");
      print(
"<a href=\"index.php3?mode=login\">Click here to try again</a>");
      
    }
  
?>

:: Command execute ::

Enter:
 
Select:
 

:: Search ::
  - regexp 

:: Upload ::
 
[ Read-Only ]

:: Make Dir ::
 
[ Read-Only ]
:: Make File ::
 
[ Read-Only ]

:: Go Dir ::
 
:: Go File ::
 

--[ c99shell v. 1.0 pre-release build #16 powered by Captain Crunch Security Team | http://ccteam.ru | Generation time: 0.0031 ]--