daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

overview.md (4631B)


      1 ---
      2 title: "Drupal"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-web/drupal/README.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/drupal/README.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: true
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Drupal
     14 
     15 ## Discovery
     16 
     17 - Check **meta**
     18 
     19 ```bash
     20 curl https://www.drupal.org/ | grep 'content="Drupal'
     21 ```
     22 
     23 - **Node**: Drupal content entities of the node type represent items such as articles and pages. Canonical routes commonly use `/node/<nodeid>`, although aliases can hide that route.<sup>[[2]](#references)</sup>
     24 
     25 ```bash
     26 curl drupal-site.com/node/1
     27 ```
     28 
     29 ## Enumeration
     30 
     31 ### Version
     32 
     33 - Check `/CHANGELOG.txt`
     34 
     35 ```bash
     36 curl -s http://drupal-site.local/CHANGELOG.txt | grep -m2 ""
     37 
     38 Drupal 7.57, 2018-02-21
     39 ```
     40 
     41 > [!TIP]
     42 > Newer installs of Drupal by default block access to the `CHANGELOG.txt` and `README.txt` files.
     43 
     44 ### Username enumeration
     45 
     46 Drupal installs define the following broad roles by default; permissions and any additional roles are site-configurable:<sup>[[3]](#references)</sup>
     47 
     48 1. **`Administrator`**: This user has complete control over the Drupal website.
     49 2. **`Authenticated User`**: These users can log in to the website and perform operations such as adding and editing articles based on their permissions.
     50 3. **`Anonymous`**: All website visitors are designated as anonymous. By default, these users are only allowed to read posts.
     51 
     52 **To enumerate users you can:**
     53 
     54 - **Profile probing:** Request `/user/1`, `/user/2`, `/user/3` and compare status, body, redirects, and timing. This only enumerates users when the site exposes distinguishable responses.
     55 - **Registry**: Access`/user/register` and try to create a username and if the name is already taken it will be indicated in an error from the server.
     56 - **Reset password**: Try to reset the password of a user and if the user doesn't exist it will be indicated clearly in an error message.
     57 
     58 ### Hidden pages
     59 
     60 Just find new pages by looking into **`/node/FUZZ`** where **`FUZZ`** is a number (from 1 to 1000 for example).
     61 
     62 ### Installed modules info
     63 
     64 Exposed configuration-synchronization files may reveal enabled modules and service settings.<sup>[[5]](#references)</sup>
     65 
     66 ```bash
     67 # Technique shared by Intigriti; see reference 5
     68 #Get info on installed modules
     69 curl https://example.com/config/sync/core.extension.yml
     70 curl https://example.com/core/core.services.yml
     71 
     72 # Download content from files exposed in the previous step
     73 curl https://example.com/config/sync/swiftmailer.transport.yml
     74 ```
     75 
     76 ## Automatic Tools
     77 
     78 ```bash
     79 droopescan scan drupal -u http://drupal-site.local
     80 ```
     81 
     82 `droopescan` fingerprints CMS versions, plug-ins, and themes; validate its findings manually because content filtering and customized paths can cause false results.<sup>[[4]](#references)</sup>
     83 
     84 ## RCE
     85 
     86 If you have access to the Drupal web console check these options to get RCE:
     87 
     88 
     89 [Drupal Rce](/hacktricks/network-services-pentesting/pentesting-web/drupal/drupal-rce)
     90 
     91 ## From XSS to RCE
     92 
     93 - **Drupalwned** is a Drupal exploitation script whose documented chains can elevate XSS into RCE or other critical impact.<sup>[[1]](#references)[[6]](#references)</sup> Its documented targets include Drupal 7.x through 10.x, and it supports:
     94   - _**Privilege Escalation:**_ Creates an administrative user in Drupal.
     95   - _**(RCE) Upload Template:**_ Upload custom templates backdoored to Drupal.
     96 
     97 ## Post Exploitation
     98 
     99 ### Read settings.php
    100 
    101 ```bash
    102 find / -name settings.php -exec grep "drupal_hash_salt\|'database'\|'username'\|'password'\|'host'\|'port'\|'driver'\|'prefix'" {} \; 2>/dev/null
    103 ```
    104 
    105 ### Dump users from DB
    106 
    107 ```bash
    108 mysql -u drupaluser --password='2r9u8hu23t532erew' -e 'use drupal; select * from users'
    109 ```
    110 
    111 ## References
    112 
    113 - [1] [Elevating Low Vulnerabilities to Critical in CMSs and E-Commerce Platforms](https://nowak0x01.github.io/papers/76bc0832a8f682a7e0ed921627f85d1d.html)
    114 - [2] [Drupal documentation — Concept: Content entities and fields](https://www.drupal.org/docs/user_guide/en/planning-data-types.html)
    115 - [3] [Drupal documentation — Concept: Users, roles, and permissions](https://www.drupal.org/docs/user_guide/en/user-concept.html)
    116 - [4] [SamJoan/droopescan](https://github.com/SamJoan/droopescan)
    117 - [5] [Intigriti — exposed Drupal configuration synchronization files](https://twitter.com/intigriti/status/1439192489093644292)
    118 - [6] [nowak0x01/Drupalwned](https://github.com/nowak0x01/Drupalwned)