overview.md (4631B)
1 --- 2 title: "Drupal" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/pentesting-web/drupal/README.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/drupal/README.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: true 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Drupal 14 15 ## Discovery 16 17 - Check **meta** 18 19 ```bash 20 curl https://www.drupal.org/ | grep 'content="Drupal' 21 ``` 22 23 - **Node**: Drupal content entities of the node type represent items such as articles and pages. Canonical routes commonly use `/node/<nodeid>`, although aliases can hide that route.<sup>[[2]](#references)</sup> 24 25 ```bash 26 curl drupal-site.com/node/1 27 ``` 28 29 ## Enumeration 30 31 ### Version 32 33 - Check `/CHANGELOG.txt` 34 35 ```bash 36 curl -s http://drupal-site.local/CHANGELOG.txt | grep -m2 "" 37 38 Drupal 7.57, 2018-02-21 39 ``` 40 41 > [!TIP] 42 > Newer installs of Drupal by default block access to the `CHANGELOG.txt` and `README.txt` files. 43 44 ### Username enumeration 45 46 Drupal installs define the following broad roles by default; permissions and any additional roles are site-configurable:<sup>[[3]](#references)</sup> 47 48 1. **`Administrator`**: This user has complete control over the Drupal website. 49 2. **`Authenticated User`**: These users can log in to the website and perform operations such as adding and editing articles based on their permissions. 50 3. **`Anonymous`**: All website visitors are designated as anonymous. By default, these users are only allowed to read posts. 51 52 **To enumerate users you can:** 53 54 - **Profile probing:** Request `/user/1`, `/user/2`, `/user/3` and compare status, body, redirects, and timing. This only enumerates users when the site exposes distinguishable responses. 55 - **Registry**: Access`/user/register` and try to create a username and if the name is already taken it will be indicated in an error from the server. 56 - **Reset password**: Try to reset the password of a user and if the user doesn't exist it will be indicated clearly in an error message. 57 58 ### Hidden pages 59 60 Just find new pages by looking into **`/node/FUZZ`** where **`FUZZ`** is a number (from 1 to 1000 for example). 61 62 ### Installed modules info 63 64 Exposed configuration-synchronization files may reveal enabled modules and service settings.<sup>[[5]](#references)</sup> 65 66 ```bash 67 # Technique shared by Intigriti; see reference 5 68 #Get info on installed modules 69 curl https://example.com/config/sync/core.extension.yml 70 curl https://example.com/core/core.services.yml 71 72 # Download content from files exposed in the previous step 73 curl https://example.com/config/sync/swiftmailer.transport.yml 74 ``` 75 76 ## Automatic Tools 77 78 ```bash 79 droopescan scan drupal -u http://drupal-site.local 80 ``` 81 82 `droopescan` fingerprints CMS versions, plug-ins, and themes; validate its findings manually because content filtering and customized paths can cause false results.<sup>[[4]](#references)</sup> 83 84 ## RCE 85 86 If you have access to the Drupal web console check these options to get RCE: 87 88 89 [Drupal Rce](/hacktricks/network-services-pentesting/pentesting-web/drupal/drupal-rce) 90 91 ## From XSS to RCE 92 93 - **Drupalwned** is a Drupal exploitation script whose documented chains can elevate XSS into RCE or other critical impact.<sup>[[1]](#references)[[6]](#references)</sup> Its documented targets include Drupal 7.x through 10.x, and it supports: 94 - _**Privilege Escalation:**_ Creates an administrative user in Drupal. 95 - _**(RCE) Upload Template:**_ Upload custom templates backdoored to Drupal. 96 97 ## Post Exploitation 98 99 ### Read settings.php 100 101 ```bash 102 find / -name settings.php -exec grep "drupal_hash_salt\|'database'\|'username'\|'password'\|'host'\|'port'\|'driver'\|'prefix'" {} \; 2>/dev/null 103 ``` 104 105 ### Dump users from DB 106 107 ```bash 108 mysql -u drupaluser --password='2r9u8hu23t532erew' -e 'use drupal; select * from users' 109 ``` 110 111 ## References 112 113 - [1] [Elevating Low Vulnerabilities to Critical in CMSs and E-Commerce Platforms](https://nowak0x01.github.io/papers/76bc0832a8f682a7e0ed921627f85d1d.html) 114 - [2] [Drupal documentation — Concept: Content entities and fields](https://www.drupal.org/docs/user_guide/en/planning-data-types.html) 115 - [3] [Drupal documentation — Concept: Users, roles, and permissions](https://www.drupal.org/docs/user_guide/en/user-concept.html) 116 - [4] [SamJoan/droopescan](https://github.com/SamJoan/droopescan) 117 - [5] [Intigriti — exposed Drupal configuration synchronization files](https://twitter.com/intigriti/status/1439192489093644292) 118 - [6] [nowak0x01/Drupalwned](https://github.com/nowak0x01/Drupalwned)